ACL Control Configuration
147
Configuration Tasks
Table 157
lists the commands that you can execute to configure TELNET or SSH
user ACL.
By default, the incoming/outgoing calls are not restricted on the user interface.
■
You can only use number-based ACLs for TELNET or SSH user ACL control.
■
When TELNET or SSH users use basic or advanced ACLs, the incoming/outgoing
calls are restricted on the basis of the source or destination IP address. As a
result, when you use the rules for basic and advanced ACLs, only the source IP
and the corresponding mask, the destination IP and the corresponding mask,
and the time-range keyword take effect. When TELNET and SSH users use L2
Table 157
Commands for Configuring TELNET/SSH User ACL
To
In This View
Type This Command
Description
Enter system
view
system-view
Define ACLs and
enter ACL view
acl number acl-number [
match-order { config |
auto } ]
Required. You can only
define number-based
ACLs here.
Define rules
Basic ACL view
rule [ rule-id ] { permit
| deny } [ source {
source-addr wildcard |
any } | fragment {source
[source-addr wildcard |
any ]}]
When TELNET and SSH
users use basic and
advanced ACLs, only
the source IP and the
corresponding mask,
the destination IP and
the corresponding
mask, and the
time-range keyword in
the rule parameters
take effect.
Define rules
Advanced ACL
view
r rule rule-id { permit
| deny } protocol
[source { source-addr
wildcard | any } ]
| [destination {
dest-addr wildcard | any
} ] | [ icmp-type type
code ] | [precedence pre-
cedence ] | [tos tos ]
| [dscp dscp ] |
[ fragment ]
When TELNET and SSH
users use basic and
advanced ACLs, only
the source IP and the
corresponding mask,
the destination IP and
the corresponding
mask, and the
time-range keyword in
the rule parameters
take effect.
Quit ACL view
quit
Enter user
interface view
user-interface [ type ]
first-number
Use ACLs, and
restrict
incoming/outgoi
ng calls for
TELNET or SSH
users
Basic or
advanced
ACLs
acl acl-number1 {
inbound | outbound }
The acl-number1
parameter indicates
basic or advanced ACL
number, in the range
of 2,000 to 3,999.
Use L2 ACLs
acl acl-number2 inbound
The acl-number2
parameter indicates
the L2 ACL number, in
the range of 4,000 to
4,999.
Summary of Contents for 400 Family
Page 12: ......
Page 16: ...14 ABOUT THIS GUIDE ...
Page 58: ...56 CHAPTER 2 PORT OPERATION ...
Page 68: ...66 CHAPTER 3 VLAN OPERATION ...
Page 98: ...96 CHAPTER 5 NETWORK PROTOCOL OPERATION ...
Page 124: ...122 CHAPTER 6 IP ROUTING PROTOCOL OPERATION ...
Page 156: ...154 CHAPTER 8 ACL CONFIGURATION ...
Page 218: ...216 CHAPTER 11 802 1X CONFIGURATION ...
Page 298: ...296 CHAPTER 13 PASSWORD CONTROL CONFIGURATION OPERATIONS ...
Page 336: ...334 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP ...