Standard IP ACL Commands
When you create an ACL without any rule and then apply it to an interface, the ACL behavior reflects an implicit permit.
The C-Series and S-Series platforms (except the S4810) support Ingress IP ACLs only.
The S4810 and Z9000 support both Ingress and Egress IP ACLs.
NOTE: Also refer to the
Commands Common to all ACL Types
and
Common IP ACL Commands
sections.
deny
Configure a filter to drop packets with a certain IP address.
C-Series, E-Series, S-Series, Z-Series, S4810
Syntax
deny {
source
[
mask
] | any | host
ip-address
} [count [byte] |
log] [dscp
value
] [order] [monitor] [fragments]
To remove this filter, you have two choices:
•
Use the
no seq
sequence-number
command if you know the filter’s sequence
number.
•
Use the
no deny {
source
[
mask
] | any | host
ip-address
}
command.
Parameters
source
Enter the IP address in dotted decimal format of the network from
which the packet was sent.
mask
(OPTIONAL) Enter a network mask in /prefix format (/x) or A.B.C.D.
The mask, when specified in A.B.C.D format, may be either
contiguous or non-contiguous (discontiguous).
any
Enter the keyword
any
to specify that all routes are subject to the
filter.
host
ip-address
Enter the keyword
host
and then enter the IP address to specify a
host IP address only.
count
(OPTIONAL) Enter the keyword
count
to count packets processed
by the filter.
byte
(OPTIONAL) Enter the keyword
byte
to count bytes processed by
the filter.
log
(OPTIONAL, E-Series only) Enter the keyword
log
to enter ACL
matches in the log.
dscp
(OPTIONAL) Enter the keyword
dcsp
to match to the IP DCSCP
values.
order
(OPTIONAL) Enter the keyword
order
to specify the QoS order of
priority for the ACL entry. The range is 0 to 254 (where 0 is the highest
priority and 254 is the lowest; lower order numbers have a higher
priority). The default is, if you do not use the keyword
order
, the
ACLs have the lowest order by default (255).
218
Summary of Contents for Force10 Z9000
Page 1: ...FTOS Command Line Reference Guide for the Z9000 System FTOS 9 1 0 0 ...
Page 96: ...96 ...
Page 194: ...194 ...
Page 312: ...312 ...
Page 540: ...540 ...
Page 546: ...546 ...
Page 560: ...560 ...
Page 566: ...566 ...
Page 590: ...action act UpdateCounter param0 1 0x01 param1 0 0x00 output truncated 590 ...
Page 624: ...624 ...
Page 638: ...638 ...
Page 648: ...648 ...
Page 659: ...Related Commands show gvrp displays the GVRP configuration 659 ...
Page 660: ...660 ...
Page 834: ...834 ...
Page 854: ...854 ...
Page 906: ...906 ...
Page 914: ...914 ...
Page 976: ...976 ...
Page 990: ...990 ...
Page 1006: ...1006 ...
Page 1008: ...1008 ...
Page 1026: ...1026 ...
Page 1145: ...10 211 1 2 Outgoing interface list GigabitEthernet 8 0 1145 ...
Page 1146: ...1146 ...
Page 1156: ...1156 ...
Page 1166: ...1166 ...
Page 1180: ...1180 ...
Page 1258: ...1258 ...
Page 1272: ...1272 ...
Page 1394: ...1394 ...
Page 1400: ...1400 ...
Page 1410: ...1410 ...
Page 1424: ...1424 ...
Page 1444: ...1444 ...
Page 1468: ...Version 8 3 8 0 Introduced on the S4810 1468 ...
Page 1470: ...1470 ...