![]() |
• ALL• TCP• UDP• ICMP• GRE• ESP• AH Source IP/mask
Destination IP/mask A host IP address or subnetwork IP address in the form: hostIPaddress or networkIPaddress/NN. If you specify a source IP, incoming packets are filtered for the specified IP address. If you specify a destination IP, outgoing packets are filtered for the specified IP address. • Accept• Drop• RejectAny of the options in Table 4.21 can be given the inverted flag, so that the target action is performed on packets that do not match any of the specified criteria. For example, if DROP is the target action, if Inverted is specified for a source IP address and if no other criteria are specified in the rule, any packets arriving from any other source IP address are dropped.