BigIron RX Series Configuration Guide
559
53-1001810-01
ICMP filtering for extended ACLs
21
Named ACLs
For example, to deny the administratively-prohibited message type in a named ACL, enter
commands such as the following.
BigIron RX
(config)# ip access-list extended entry
BigIron RX
(config-ext-nacl)# deny ICMP any any administratively-prohibited
or
BigIron RX
(config)# ip access-list extended entry
BigIron RX
(config-ext-nacl)#deny ICMP any any 3 13
Syntax: [no]ip access-list extended
<acl-name>
deny | permit host icmp any any [log]
<icmp-type>
|
<type-number>
<code-number>
The extended parameter indicates the ACL entry is an extended ACL.
The
<acl-name>
|
<acl-num>
parameter allows you to specify an ACL name or number. If using a
name, specify a string of up to 256 alphanumeric characters. You can use blanks in the ACL name
if you enclose the name in quotation marks (for example, “ACL for Net1”). The
<acl-num>
parameter allows you to specify an ACL number if you prefer. If you specify a number, enter a
number from 100 – 199 for extended ACLs.
The deny | permit parameter indicates whether packets that match the policy are dropped or
forwarded.
You can either use the
<icmp-type>
and enter the name of the message type or use the
<type-number>
<code-number>
parameter to enter the type number and code number of the
message. Refer to
Table 99
on page 559 for valid values.
TABLE 99
ICMP message types and codes
ICMP message type
Type
Code
administratively-prohibited
3
13
any-icmp-type
x
x
destination-host-prohibited
3
10
destination-host-unknown
3
7
NOTE: destination-net-prohibited
3
9
destination-network-unknown
3
6
echo
8
0
echo-reply
0
0
general-parameter-problem
NOTE: This message type indicates that required
option is missing.
12
1
host-precedence-violation
3
14
host-redirect
5
1
host-tos-redirect
5
3
host-tos-unreachable
3
12
host-unreachable
3
1
information-request
15
0
Summary of Contents for Brocade DCX
Page 40: ...xl BigIron RX Series Configuration Guide 53 1001810 01 ...
Page 72: ...lxxii BigIron RX Series Configuration Guide 53 1001810 01 ...
Page 88: ...16 BigIron RX Series Configuration Guide 53 1001810 01 Searching and filtering output 1 ...
Page 300: ...228 BigIron RX Series Configuration Guide 53 1001810 01 Displaying IP information 7 ...
Page 318: ...246 BigIron RX Series Configuration Guide 53 1001810 01 Deploying a LAG 8 ...
Page 418: ...346 BigIron RX Series Configuration Guide 53 1001810 01 SuperSpan 12 ...
Page 482: ...410 BigIron RX Series Configuration Guide 53 1001810 01 MRP CLI example 14 ...
Page 506: ...434 BigIron RX Series Configuration Guide 53 1001810 01 Displaying VSRP information 15 ...
Page 582: ...510 BigIron RX Series Configuration Guide 53 1001810 01 Viewing Layer 2 ACLs 20 ...
Page 634: ...562 BigIron RX Series Configuration Guide 53 1001810 01 Troubleshooting ACLs 21 ...
Page 642: ...570 BigIron RX Series Configuration Guide 53 1001810 01 Trunk formation 22 ...
Page 746: ...674 BigIron RX Series Configuration Guide 53 1001810 01 Displaying RIP filters 24 ...
Page 808: ...736 BigIron RX Series Configuration Guide 53 1001810 01 Displaying OSPF information 25 ...
Page 938: ...866 BigIron RX Series Configuration Guide 53 1001810 01 Displaying MBGP information 27 ...
Page 950: ...878 BigIron RX Series Configuration Guide 53 1001810 01 Using secure copy 28 ...
Page 988: ...916 BigIron RX Series Configuration Guide 53 1001810 01 Clearing IS IS information 29 ...
Page 1054: ...982 BigIron RX Series Configuration Guide 53 1001810 01 Sample 802 1x configurations 33 ...
Page 1108: ...1036 BigIron RX Series Configuration Guide 53 1001810 01 sFlow 39 ...
Page 1190: ...1118 BigIron RX Series Configuration Guide 53 1001810 01 Displaying RIPng information 44 ...
Page 1270: ...1198 BigIron RX Series Configuration Guide 53 1001810 01 Displaying ACLs 47 ...
Page 1310: ...1238 BigIron RX Series Configuration Guide 53 1001810 01 Displaying OSPFv3 information 48 ...
Page 1382: ...1310 BigIron RX Series Configuration Guide 53 1001810 01 Commands That Require a Reload D ...
Page 1435: ...BigIron RX Series Configuration Guide 1363 53 1001810 01 VSRP E ...
Page 1436: ...1364 BigIron RX Series Configuration Guide 53 1001810 01 VSRP E ...