ip access-list session
ip access-list session <accname>
<source> <dest> <service> <action> [<extended action>]
ipv6 [alias | any | host | network | user]
no ...
Description
This command configures an access control list (ACL) session. To create IPv6 specific rules, use the
ipv6
keyword.
Syntax
Parameter
Description
<accname>
Name of an access control list session.
ipv6
Use the ipv6 keyword to create IPv6 specific rules.
<source>
The traffic source, which can be one of the following:
alias: specify the network resource (use the netdestination command to configure aliases; use the
show netdestination command to see configured aliases)
any: match any traffic
host: specify a single host IP address
localip: specify the local IP address to match traffic
network: specify the IP address and netmask
user: represents the IP address of the user
<dest>
The traffic destination, which can be one of the following:
alias: specify the network resource (use the netdestination command to configure aliases; use the
show netdestination command to see configured aliases)
any: match any traffic
host: specify a single host IP address
localip: specify the local IP address to match traffic
network: specify the IP address and netmask
user: represents the IP address of the user
<service>
Network service, which can be one of the following:
IP protocol number (0-255)
name of a network service (use the show netservice command to see configured services)
any: match any traffic
tcp: specify the TCP port number (0-65535)
udp: specify the UDP port number (0-65535)
<action>
Action if rule is applied, which can be one of the following:
deny: Reject packets
dst-nat: Performs destination NAT on packets. Forward packets from source network to destination;
re-mark them with destination IP of the target network. This action functions in tunnel/decrypt-tunnel
forwarding mode. User should configure the NAT pool in the controller.
dual-nat: Performs both source and destination NAT on packets. Source IP and destination IP is
changed as per the NAT pool configured. This action functions in tunnel/decrypt-tunnel forwarding
mode. User should configure the NAT pool in the controller.
permit: Forward packets.
redirect: Specify the location to which packets are redirected, which can be one of the following:
l
Datapath destination ID (0-65535).
l
esi-group: Specify the ESI server group configured with the esi group command.
Dell PowerConnect W-Series ArubaOS 6.2 |
Reference Guide
ip access-list session | 353
Summary of Contents for PowerConnect W-7200 Series
Page 1: ...Dell PowerConnect W Series ArubaOS 6 2 Command Line Interface Reference Guide ...
Page 38: ...38 aaa authentication server windows DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 319: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide interface loopback 319 ...
Page 346: ...346 ipv6 mld DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 387: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide ip radius 387 ...
Page 995: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide show firewall 995 ...
Page 1529: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide wms client 1529 ...
Page 1536: ...0510956 01 March 2013 1536 ...