This appendix includes the following topics:
Figure B-1 shows an example rule in which the source value Ipaddress/NM has been replaced with the =ListName value. This rule permits users on the internal_hosts list to telnet to the host at 192.160.240.10.
permit =internal_hosts 192.168.240.10 tcp dst eq 23
|
Figure B-2 shows an example rule in which the destination value Ipaddress(dest)/NM has been replaced with the =ListName value. This rule permits users from the source IP address 172.30.00/16 to access any Web sites on the yahooligans list.
permit 172.30.0.0/16 =yahooligans tcp dst eq 80
|
permit|deny [Ipaddress/NM Ipaddress(dest)/NM] [log] [notify]
or
permit|deny =ListName Ipaddress(dest)/NM [log] [notify]
or
permit|deny Ipaddress/NM =ListName [log] [notify]
|
permit|deny [Ipaddress/NM Ipaddress(dest)/NM] tcp [src eq|lt|gt Tport] [dst eq|lt|gt Tport]
[established] [log] [notify]
or
permit|deny =ListName Ipaddress(dest)/NM tcp [src eq|lt|gt Tport] [dst eq|lt|gt Tport]
[established] [log] [notify]
or
permit|deny Ipaddress/NM =ListName tcp [src eq|lt|gt Tport] [dst eq|lt|gt Tport]
[established] [log] [notify]
|
permit|deny [Ipaddress/NM Ipaddress(dest)/NM] udp [src eq|lt|gt Uport] [dst eq|lt|gt Uport]
[log] [notify]
or
permit|deny =ListName Ipaddress(dest)/NM udp [src eq|lt|gt Uport] [dst eq|lt|gt Uport] [log]
[notify]
or
permit|deny Ipaddress/NM =ListName udp [src eq|lt|gt Uport] [dst eq|lt|gt Uport] [log]
[notify]
|
permit|deny [Ipaddress/NM Ipaddress(dest)/NM] icmp [type Itype] [log] [notify]
or
permit|deny =ListName Ipaddress(dest)/NM icmp [type Itype] [log] [notify]
or
permit|deny Ipaddress/NM =ListName icmp [type Itype] [log] [notify]
|