18. Access Lists
354
ip access-list extended
Configures an access list to serve as an IPv4 filter. There are two types of access lists that operate
as IPv4 filters. One type is an IPv4 address filter and the other type is an IPv4 packet filter.
This command sets an IPv4 packet filter.
An IPv4 packet filter filters based on source IPv4 address, destination IPv4 address, VLAN ID,
user priority, ToS field value, port number, TCP flag, ICMP type, and ICMP code.
A maximum of 1024 access lists (for IPv4, IPv6, and MAC) can be created per device. A maximum
of 1024 filter condition entries can be created.
For details about access lists, see
Number of access lists that can be created
.
If you specify
permit
for the filter action, you can specify parameters for policy-based routing. If
you use access group commands to apply the target access list to an interface, specify the inbound
side of the VLAN interface. [AX3640S] [OS-L3A]
Syntax
To set information:
ip access-list extended {
<access list number>
|
<access list name>
}
To delete information:
no ip access-list extended {
<access list number>
|
<access list name>
}
Input mode
(config)
Parameters
{
<access list number>
|
<access list name>
}
Specifies the identifier of the IPv4 packet filter that is to be set.
1.
Default value when this parameter is omitted:
This parameter cannot be omitted.
2.
Range of values:
For
<access list number>
, specify values from 100 to 199, or from 2000 to 2699 (in
decimal).
For
<access list name>
, specify a name that is no more than 31 characters.
Specifiable values for parameters
.
Default behavior
None
Impact on communication
None
When the change is applied
The change is applied immediately after setting values are changed.
Notes
1.
For
<access list number>
, you can use 100 to 199 or 2000 to 2699 in the
access-list
command.
Summary of Contents for AX3630S
Page 16: ......
Page 43: ...15 Chapter 3 Editing and Working with Configurations end quit exit save write show status top...
Page 59: ...4 Login Security and RADIUS or TACACS 31 tacacs server...
Page 63: ...4 Login Security and RADIUS or TACACS 35 aaa authentication login end by reject...
Page 77: ...4 Login Security and RADIUS or TACACS 49 ip access group ipv6 access list...
Page 92: ......
Page 95: ...5 Time Settings and NTP 67 Notes None Related commands set clock show clock show logging...
Page 100: ...5 Time Settings and NTP 72 ntp master ntp authenticate ntp trusted key ntp broadcast client...
Page 125: ...7 Device Management 97 Notes None Related commands None...
Page 164: ......
Page 178: ...10 Link Aggregation 150 channel group max active port...
Page 194: ...12 VLAN 166 Related commands mac based vlan static only...
Page 217: ...12 VLAN 189 Related commands None...
Page 224: ...12 VLAN 196 Related commands vlan mac...
Page 240: ...13 Spanning Tree Protocol 212 spanning tree single mode...
Page 276: ...13 Spanning Tree Protocol 248 Related commands None...
Page 285: ...13 Spanning Tree Protocol 257 Related commands None...
Page 287: ...13 Spanning Tree Protocol 259 spanning tree vlan mode...
Page 288: ......
Page 292: ...14 Ring Protocol 264 Related commands vlan...
Page 318: ......
Page 324: ...15 IGMP Snooping 296 Related commands ip igmp snooping...
Page 326: ......
Page 331: ...16 MLD Snooping 303 Related commands ipv6 mld snooping...
Page 340: ......
Page 389: ...18 Access Lists 361 remark...
Page 391: ...18 Access Lists 363 Related commands ipv6 access list...
Page 400: ...18 Access Lists 372 Related commands mac access list extended...
Page 420: ......
Page 436: ...19 QoS 408 Related commands ip qos flow list...
Page 442: ...19 QoS 414 Related commands ipv6 qos flow list...
Page 449: ...19 QoS 421 Related commands mac qos flow list...
Page 484: ......
Page 509: ...21 IEEE802 1X 481 dot1x multiple authentication...
Page 519: ...21 IEEE802 1X 491 dot1x system auth control dot1x port control...
Page 534: ...21 IEEE802 1X 506 dot1x system auth control dot1x vlan dynamic enable...
Page 547: ...21 IEEE802 1X 519 dot1x vlan enable...
Page 551: ...21 IEEE802 1X 523 Related commands dot1x system auth control dot1x vlan enable...
Page 555: ...21 IEEE802 1X 527 Related commands dot1x system auth control dot1x vlan enable...
Page 560: ......
Page 592: ......
Page 598: ...23 MAC based Authentication 570 mac authentication port...
Page 615: ...24 Authentication VLANs OP VAA 587 fense vlan...
Page 626: ......
Page 638: ...25 DHCP Snooping 610 ip dhcp snooping vlan...
Page 678: ...28 VRRP 650 track interface track ip route vrrp ip vrrp track...
Page 680: ...28 VRRP 652 ip address track interface track ip route vrrp ip vrrp track...
Page 682: ...28 VRRP 654 track ip route vrrp ip vrrp track...
Page 684: ...28 VRRP 656 track interface track ip route vrrp ip vrrp track...
Page 690: ...28 VRRP 662 track ip route vrrp ip vrrp track...
Page 692: ...28 VRRP 664 track interface track ip route vrrp ip vrrp track...
Page 717: ...689 Chapter 31 Storm Control storm control...
Page 739: ...33 CFM 711 ma vlan group...
Page 743: ...33 CFM 715 Related commands domain name ethernet cfm cc enable ma name ma vlan group...
Page 790: ......
Page 793: ...35 Log Data Output Functionality 765 ip domain name ip name server ip domain lookup...
Page 805: ...35 Log Data Output Functionality 777 Related commands logging host...
Page 806: ......
Page 819: ...36 sFlow Statistics 791 Notes None Related commands None...
Page 828: ......
Page 836: ......
Page 837: ...809 PART 14 Port Mirroring Chapter 39 Port Mirroring monitor session...