116
|
Access Control Lists (ACL)
www.dell.com | support.dell.com
Defaults
Not configured
Command Modes
CONFIGURATION-IP ACCESS-LIST-EXTENDED
Command
History
ip
Enter the keyword
ip
to configure a generic IP access list. The keyword
ip
specifies
that the access list will permit all IP protocols.
tcp
Enter the keyword
tcp
to configure a TCP access list filter.
udp
Enter the keyword
udp
to configure a UDP access list filter.
source
Enter the IP address of the network or host from which the packets were sent.
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask, when specified in
A.B.C.D format, may be either contiguous or non-contiguous.
any
Enter the keyword
any
to specify that all routes are subject to the filter.
host
ip-address
Enter the keyword
host
followed by the IP address to specify a host IP address.
operator
(OPTIONAL) Enter one of the following logical operands:
•
eq
= equal to
•
neq
= not equal to
•
gt
= greater than
•
lt
= less than
•
range
= inclusive range of ports (you must specify two ports for the
port
parameter.)
port
port
(OPTIONAL) Enter the application layer port number. Enter two port numbers if
using the
range
logical operand.
Range: 0 to 65535
The following list includes some common TCP port numbers:
•
23 = Telnet
•
20 and 21 = FTP
•
25 = SMTP
•
169 = SNMP
destination
Enter the IP address of the network or host to which the packets are sent.
message-type
(OPTIONAL) Enter an ICMP message type, either with the type (and code, if
necessary) numbers or with the name of the message type (ICMP message types are
listed in
Table 6-2
).
Range: 0 to 255 for ICMP type; 0 to 255 for ICMP code
count
(OPTIONAL) Enter the keyword
count
to count packets processed by the filter.
byte
(OPTIONAL) Enter the keyword
byte
to count bytes processed by the filter.
dscp
(OPTIONAL) Enter the keyword
dscp
to match to the IP DSCP values.
order
(OPTIONAL) Enter the keyword
order
to specify the QoS priority for the ACL
entry.
Range:
0-254 (where 0 is the highest priority and 254 is the lowest; lower order
numbers have a higher priority)
Default:
If the order keyword is not used, the ACLs have the lowest order by
default (255).
fragments
Enter the keyword
fragments
to use ACLs to control packet fragments.
Version 8.3.16.1
Introduced on MXL 10/40GbE Switch IO Module
Summary of Contents for Force10 MXL Blade
Page 80: ...80 Control and Monitoring w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 142: ...142 Access Control Lists ACL w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 146: ...146 Bare Metal Provisioning w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 152: ...152 Content Addressable Memory CAM w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 186: ...186 Data Center Bridging w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 204: ...204 Dynamic Host Configuration Protocol DHCP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 216: ...216 FIP Snooping w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 226: ...226 GARP VLAN Registration GVRP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 234: ...234 Internet Group Management Protocol IGMP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 330: ...330 iSCSI Optimization w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 354: ...354 Layer 2 w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 370: ...370 Link Layer Discovery Protocol LLDP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 384: ...384 Multiple Spanning Tree Protocol MSTP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 438: ...438 Port Monitoring w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 448: ...448 Private VLAN PVLAN w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 490: ...490 Quality of Service QoS w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 518: ...518 Remote Monitoring RMON w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 530: ...530 Rapid Spanning Tree Protocol RSTP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 570: ...570 Security w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 578: ...578 sFlow w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 620: ...620 Stacking Commands w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 654: ...654 Uplink Failure Detection UFD w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 693: ...Debugging and Diagnostics 693 ...
Page 694: ...694 Debugging and Diagnostics w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 712: ...712 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 713: ...Index 713 ...
Page 714: ...714 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 715: ...Index 715 ...
Page 716: ...716 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 717: ...Index 717 ...
Page 718: ...718 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 728: ...728 Command Index w w w d e l l c o m s u p p o r t d e l l c o m write 78 write memory 25 ...
Page 729: ...Command Index 729 ...
Page 730: ...730 Command Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 731: ...Command Index 731 ...
Page 732: ...732 Command Index w w w d e l l c o m s u p p o r t d e l l c o m ...