SonicOS 7 Match Objects

Configuration Example

Assume an administrator needs to allow RSVP (Resource Reservation Protocol - IP Type 46) and SRP (Spectralink™ Radio Protocol – IP type 119) from all clients on the WLAN zone (WLAN Subnets) to a server on the LAN zone (for example, 10.50.165.26). You can define custom IP type service objects to handle these two services.

To define a custom IP type service and related configuration:

  1. Navigate to Object > Match Objects > Services > Service Objects page.
  2. Click the Add button. The Service Objects dialog displays.

  3. Enter a descriptive name for the service object in the Name field.

  4. Select Custom IP type from the Protocol drop-down menu.

  5. In the field to the right of the Protocol drop-down list, type in the protocol number for the Custom IP Type.

    The Port Range and Sub Type fields are not definable or applicable to a Custom IP Type.

    Attempts to define a custom protocol type service object for a predefined IP type is not permitted and results in an error message.

  6. Click Save.
  7. Repeat Step 3 through Step 6 for each custom service to be defined.
  8. Navigate to Object > Match Objects > Services > Service Groups page.
  9. Click the Add button. The Service Groups dialog displays.

  10. Enter a descriptive name for the service group in the Name field, such as myServices.
  11. Select the custom service objects you just created from the list on the left, and then click the Right Arrow button to move them into the list on the right.

    Press Ctrl or Shift to select multiple service objects, and then click the Right Arrow button to move them all at one time.

  12. Click Save.
  13. Navigate to Object > Match Objects > Services > Service Objects page.
  14. Click the Add button. The Service Objects dialog displays.
  15. Create an address object for the host that the WLAN Subnets can access using myServices.
  16. Select the custom service objects you just created from the list on the left, and then click the Right Arrow button to move them into the list on the right.

    Press Ctrl or Shift to select multiple service objects, and then click the Right Arrow button to move them all at one time.

  17. Click Save.
  18. Navigate to Policy > Rules and Policies > Access Rules page to create a WLAN > LAN rule.
  19. Define an access rule allowing myServices from WLAN Subnets to the 10.50.165.26 address object.

    It may be necessary to create an access rule for bidirectional traffic; for example, an additional access rule from the LAN > WLAN allowing myServices from 10.50.165.26 to WLAN Subnets.

  20. Click Save.

    IP protocol 46 and 119 traffic will now be recognized and allowed to pass from WLAN Subnets to the host at 10.50.165.26.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden