![Dell Brocade DCX Configuration Manual Download Page 596](http://html.mh-extra.com/html/dell/brocade-dcx/brocade-dcx_configuration-manual_85983596.webp)
524
BigIron RX Series Configuration Guide
53-1001810-01
Configuring numbered and named ACLs
21
Parameters to filter TCP or UDP packets
Use the parameters below if you want to filter traffic with the TCP or UDP packets. These
parameters apply only if you entered tcp or udp for the
<ip-protocol>
parameter. For example, if
you are configuring an entry for HTTP, specify tcp eq http.
first-fragment
Enter this keyword if you want to filter only the first-fragmented packets. Refer to
“Enabling ACL filtering of fragmented or non-fragmented packets”
on page 557.
fragment-offset
<number>
Enter this parameter if you want to filter a specific fragmented packets. Enter a
value from 0 – 8191. Refer to
“Enabling ACL filtering of fragmented or
non-fragmented packets”
on page 557.
NOTE: fragment, non-fragment, first-fragment, and fragment-offset may not be used together in the same ACL
statement.
log
Add this parameter to the end of an ACL statement to enable the generation of
SNMP traps and Syslog messages for packets denied by the ACL.You can enable
logging on ACLs and filters that support logging even when the ACLs and filters are
already in use. To do so, re-enter the ACL or filter command and add the log
parameter to the end of the ACL or filter. The software replaces the ACL or filter
command with the new one. The new ACL or filter, with logging enabled, takes
effect immediately.
NOTE: Logging must be enable on the interface to which the ACL is bound before
SNMP traps and Syslog messages can be generated, even if the log
parameter is entered. Refer to
“ACL logging”
on page 544.
<operator>
Specifies a comparison operator for the TCP or UDP port number. You can enter one
of the following operators:
•
eq – The policy applies to the TCP or UDP port name or number you enter after
eq.
•
gt – The policy applies to TCP or UDP port numbers greater than the port
number or the numeric equivalent of the port name you enter after gt.
•
lt – The policy applies to TCP or UDP port numbers that are less than the port
number or the numeric equivalent of the port name you enter after lt.
•
neq – The policy applies to all TCP or UDP port numbers except the port number
or port name you enter after neq.
•
range – The policy applies to all TCP or UDP port numbers that are between the
first TCP or UDP port name or number and the second one you enter following
the range parameter. The range includes the port names or numbers you enter.
For example, to apply the policy to all ports between and including 23 (Telnet)
and 53 (DNS), enter the following: range 23 53. The first port number in the
range must be lower than the last number in the range.
•
established – This operator applies only to TCP packets. If you use this operator,
the policy applies to TCP packets that have the ACK (Acknowledgment) or RST
(Reset) bits set on (set to “1”) in the Control Bits field of the TCP packet header.
Thus, the policy applies only to established TCP sessions, not to new sessions.
Refer to Section 3.1, “Header Format”, in RFC 793 for information about this
field.
NOTE: This operator applies only to destination TCP ports, not source TCP ports.
Summary of Contents for Brocade DCX
Page 40: ...xl BigIron RX Series Configuration Guide 53 1001810 01 ...
Page 72: ...lxxii BigIron RX Series Configuration Guide 53 1001810 01 ...
Page 88: ...16 BigIron RX Series Configuration Guide 53 1001810 01 Searching and filtering output 1 ...
Page 300: ...228 BigIron RX Series Configuration Guide 53 1001810 01 Displaying IP information 7 ...
Page 318: ...246 BigIron RX Series Configuration Guide 53 1001810 01 Deploying a LAG 8 ...
Page 418: ...346 BigIron RX Series Configuration Guide 53 1001810 01 SuperSpan 12 ...
Page 482: ...410 BigIron RX Series Configuration Guide 53 1001810 01 MRP CLI example 14 ...
Page 506: ...434 BigIron RX Series Configuration Guide 53 1001810 01 Displaying VSRP information 15 ...
Page 582: ...510 BigIron RX Series Configuration Guide 53 1001810 01 Viewing Layer 2 ACLs 20 ...
Page 634: ...562 BigIron RX Series Configuration Guide 53 1001810 01 Troubleshooting ACLs 21 ...
Page 642: ...570 BigIron RX Series Configuration Guide 53 1001810 01 Trunk formation 22 ...
Page 746: ...674 BigIron RX Series Configuration Guide 53 1001810 01 Displaying RIP filters 24 ...
Page 808: ...736 BigIron RX Series Configuration Guide 53 1001810 01 Displaying OSPF information 25 ...
Page 938: ...866 BigIron RX Series Configuration Guide 53 1001810 01 Displaying MBGP information 27 ...
Page 950: ...878 BigIron RX Series Configuration Guide 53 1001810 01 Using secure copy 28 ...
Page 988: ...916 BigIron RX Series Configuration Guide 53 1001810 01 Clearing IS IS information 29 ...
Page 1054: ...982 BigIron RX Series Configuration Guide 53 1001810 01 Sample 802 1x configurations 33 ...
Page 1108: ...1036 BigIron RX Series Configuration Guide 53 1001810 01 sFlow 39 ...
Page 1190: ...1118 BigIron RX Series Configuration Guide 53 1001810 01 Displaying RIPng information 44 ...
Page 1270: ...1198 BigIron RX Series Configuration Guide 53 1001810 01 Displaying ACLs 47 ...
Page 1310: ...1238 BigIron RX Series Configuration Guide 53 1001810 01 Displaying OSPFv3 information 48 ...
Page 1382: ...1310 BigIron RX Series Configuration Guide 53 1001810 01 Commands That Require a Reload D ...
Page 1435: ...BigIron RX Series Configuration Guide 1363 53 1001810 01 VSRP E ...
Page 1436: ...1364 BigIron RX Series Configuration Guide 53 1001810 01 VSRP E ...