This window appears when you choose an ACE for an extended IP ACL and click Modify in the Modify ACL window. It shows you all the settings for the the ACE you selected. You can change any of the settings.
This table explains the options in the window and shows which Catalyst switches support which options.
Option | Explanation | Supported by... |
Keyword | Specifies an action: permit to permit traffic from specified sources and to specified destinations or deny to deny traffic from those sources and to those destinations. | 2950 and 3550 |
Log | Specifies whether to send messages to the console for packets that match the the ACL's filtering criteria. The option log requests logging for incoming and outgoing packets; log input requests logging for only incoming packets. | 3550 only |
Precedence | Describes the priority you want to assign to packets that meet the filtering criteria. | 3550 only |
Type of Service | Specifies the type of service you want to assign to packets that meet the filtering criteria. | 3550 only |
Source Address | A field for entering an IP address or entering any, which applies the Keyword action to any source address. | 2950 and 3550 |
Source Wildcard | Specifies a mask or host, which applies the Keyword action to only the source address. The high-order bits of the mask that are binary zeros determine how many corresponding high-order bits in the IP address are significant. The selected action applies to any source address with these high-order bits. | 2950 and 3550 |
Protocol | Specifies a protocol that you want to associate this ACL with. | 2950 and 3550 |
Protocol Options | Links to a window for specifying filtering options for TCP, UDP, ICMP, or IGMP. | See Note |
Other Protocol | A field where you can enter the name of an unlisted protocol. | 3550 only |
DSCP | Specifies a DSCP if you made no selection in the Precedence or Type of Service lists. | 3550 only |
Destination Address | Means the same as Source Address, except that the filtering criteria apply to a destination rather than a source. | 2950 and 3550 |
Destination Wildcard | Means the same as Source Wildcard, except that the filtering criteria apply to a destination rather than a source. | 2950 and 3550 |
Note: For Catalyst 2950 switches, only TCP and UDP are supported.
Click OK when you finish editing the ACE.