Web
– Specify the action (i.e., Permit or Deny). Specify the source and/or
destination addresses. Select the address type (Any, Host, or IP). If you select
“Host,” enter a specific address. If you select “IP,” enter a subnet address and the
mask for an address range. Set any other required criteria, such as service type,
protocol type, or TCP control code. Then click Add.
Figure 7-3 ACL Configuration - Extended IPv4
CLI
– This example adds three rules:
1. Accept any incoming packets if the source address is in subnet 10.7.1.x. For
example, if the rule is matched; i.e., the rule (10.7.1.0 & 255.255.255.0) equals
the masked address (10.7.1.2 & 255.255.255.0), the packet passes through.
2.
Allow TCP packets from class C addresses 192.168.1.0 to any destination
address when set for destination TCP port 80 (i.e., HTTP).
3. Permit all TCP packets from class C addresses 192.168.1.0 with the TCP control
code set to “SYN.”
7
Configuring Access Control Lists
Console(config-ext-acl)#permit 10.7.1.1 255.255.255.0 any
Console(config-ext-acl)#permit tcp 192.168.1.0 255.255.255.0 any
destination-port 80
Console(config-ext-acl)#permit tcp 192.168.1.0 255.255.255.0 any
control-flag 2 2
Console(config-std-acl)#
26-3
7-5
Summary of Contents for IC40240-10G
Page 1: ...IntraCore 40240 40480 10G Layer 3 Gigabit Stackable Ethernet Switch User s Manual ...
Page 4: ...IC40240 10G 99 00837 IC40480 10G 99 00836 ...
Page 6: ...ii ...
Page 33: ...Getting Started ...
Page 43: ...1 1 10 Introduction ...
Page 61: ...2 2 18 Initial Configuration ...
Page 63: ...Switch Management ...
Page 75: ...3 3 12 Configuring the Switch ...
Page 117: ...4 4 42 Basic Management Tasks ...
Page 163: ...6 6 28 User Authentication ...
Page 175: ...7 7 12 Access Control Lists ...
Page 283: ...14 14 8 Quality of Service ...
Page 293: ...15 15 10 Multicast Filtering ...
Page 299: ...16 16 6 Domain Name Service ...
Page 309: ...17 17 10 Dynamic Host Configuration Protocol ...
Page 319: ...18 18 10 Configuring Router Redundancy ...
Page 343: ...19 19 24 IP Routing ...
Page 355: ...Web Click Routing Protocol RIP Statistics Figure 20 5 RIP Statistics 20 12 Unicast Routing 20 ...
Page 385: ...20 20 42 Unicast Routing ...
Page 387: ...Command Line Interface ...
Page 399: ...21 21 12 Overview of the Command Line Interface ...
Page 465: ...24 24 16 SNMP Commands ...
Page 519: ...26 26 18 Access Control List Commands ...
Page 545: ...30 30 2 Rate Limit Commands ...
Page 611: ...34 34 24 VLAN Commands ...
Page 625: ...35 35 14 Class of Service Commands ...
Page 633: ...36 7 police 36 ...
Page 670: ...39 39 16 DHCP Commands ...
Page 716: ...41 41 36 IP Interface Commands ...
Page 768: ...42 42 52 IP Routing Commands ...
Page 770: ...Appendices ...
Page 791: ......
Page 792: ...IC40240 10G IC40480 10G ...