![Dell C9000 series Reference Manual Download Page 296](http://html.mh-extra.com/html/dell/c9000-series/c9000-series_reference-manual_23045296.webp)
deny tcp
Configure a filter that drops transmission control protocol (TCP) packets meeting the filter criteria.
C9000 Series
Syntax
deny tcp {
source mask
| any | host
ip-address
} [
bit
] [
operator
port
[
port
]] {
destination mask
| any | host
ip-address
} [dscp]
[
bit
] [
operator port
[
port
]] [count [bytes]] [order] [fragments]
[log [interval
minutes
] [threshold-in-msgs [count]] [monitor]
To remove this filter, you have two choices:
• Use the
no seq
sequence-number
command if you know the filter’s sequence
number.
• Use the
no deny tcp {
source mask
| any | host
ip-address
}
{
destination mask
| any | host
ip-address
}
command.
Parameters
source
Enter the IP address of the network or host from which the
packets are sent.
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask,
when specified in A.B.C.D format, may be either contiguous or
non-contiguous.
any
Enter the keyword
any
to specify that all routes are subject to
the filter.
host
ip-address
Enter the keyword
host
then the IP address to specify a host IP
address.
dscp
Enter this keyword
dscp
to deny a packet based on the DSCP
value. The range is from 0 to 63.
bit
Enter a flag or combination of bits:
•
ack:
acknowledgement field
•
fin:
finish (no more data from the user)
•
psh:
push function
•
rst:
reset the connection
•
syn:
synchronize sequence numbers
•
urg:
urgent field
operator
(OPTIONAL) Enter one of the following logical operand:
•
eq
= equal to
•
neq
= not equal to
•
gt
= greater than
Access Control Lists (ACL)
296
Summary of Contents for C9000 series
Page 1: ...Dell Networking Command Line Reference Guide for the C9000 Series Version 9 10 0 0 ...
Page 394: ...deny 14551 666 Dell Access Control Lists ACL 394 ...
Page 877: ...algorithm FIPS Cryptography 877 ...
Page 1297: ...Total 5 0 Total 5 active route s using 952 bytes IPv6 Basics 1297 ...