Configuring Device Information
233
Defining MAC Based Access Control Lists
Network Security - MAC Based ACL
page allows a MAC- based ACL to be defined. ACEs can be
added only if the ACL is not bound to an interface.
To define MAC Based ACLs, click
Switch
→
Network Security
→
MAC Based ACL
.
permit {any|
protocol
} {any|{
source
source-wildcard
}}
{any|{
destination
destination-wildcard
}} [dscp
number
| ip-
precedence
number
] [fragments]
permit-icmp {any|{
source source-wildcard
}} {any|{
destination
destination-wildcard
}} {any|
icmp-type
} {any|
icmp-code
} [dscp
number
| ip-precedence
number
]
permit-igmp {any|{
source source-wildcard
}} {any|{
destination
destination-wildcard
}} {any|
igmp-type
} [dscp
number
| ip-
precedence
number
]
permit-tcp {any|{
source source-wildcard
}} {any|
source-port
}
{any|{
destination destination-wildcard
}} {any|
destination-port
}
[dscp
number
| ip-precedence
number
] [flags
list-of-flags
]
permit-udp {any|{
source source-wildcard
}} {any|
source-port
}
{any|{
destination destination-wildcard
}} {any|
destination-port
}
[dscp
number
| ip-precedence
number
]
To set conditions to allow a packet to
pass a named IP access list, use the
permit command in access list
configuration mode.
deny [disable-port] {any|
protocol
} {any|{
source source-
wildcard
}} {any|{
destination destination-wildcard
}} [dscp
number
| ip-precedence
number
] [fragments]
deny-icmp [disable-port] {any|{
source source-wildcard
}}
{any|{
destination destination-wildcard
}} {any|
icmp-type
}
{any|
icmp-code
} [dscp
number
| ip-precedence
number
]
deny-igmp [disable-port] {any|{
source source-wildcard
}}
{any|{
destination destination-wildcard
}} {any|
igmp-type
} [dscp
number
| ip-precedence
number
]
deny-tcp [disable-port] {any|{
source source-wildcard
}}
{any|
source-port
} {any|{
destination destination-wildcard
}}
{any|
destination-port
} [dscp
number
| ip-precedence
number
]
[flags
list-of-flags
]
deny-udp [disable-port] {any|{
source source-wildcard
}} {any|
source-port
} {any|{
destination destination-wildcard
}}
{any|
destination-port
} [dscp
number
| ip-precedence
number
]
To set conditions to allow a packet to
pass a named IP access list, use the deny
command in access list configuration
mode.
Table 7-5. IP Based ACL CLI Commands
(continued)
CLI Command
Description
Summary of Contents for PowerConnect 54 Series
Page 1: ...w w w d e l l c o m s u p p o r t d e l l c o m Dell PowerConnect 54xx Systems User Guide ...
Page 22: ...22 Introduction ...
Page 64: ...64 Using Dell OpenManage Switch Administrator ...
Page 214: ...214 Configuring System Information ...
Page 343: ...Configuring Device Information 343 ...
Page 344: ...344 Configuring Device Information ...
Page 381: ...Viewing Statistics 381 ...
Page 382: ...382 Viewing Statistics ...