
C
HAPTER
27
| Access Control Lists
IPv4 ACLs
– 653 –
permit
,
deny
(Extended IPv4 ACL)
This command adds a rule to an Extended IPv4 ACL. The rule sets a filter
condition for packets with specific source or destination IP addresses,
protocol types, source or destination protocol ports, or TCP control codes.
Use the
no
form to remove a rule.
S
YNTAX
{
permit
|
deny
} [
protocol
-
number |
udp
]
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
[
time-range
time-range-name
]
no
{
permit
|
deny
} [
protocol
-
number |
udp
]
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
{
permit
|
deny
}
tcp
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
[
control-flag
control-flags
flag-bitmask
]
[
time-range
time-range-name
]
no
{
permit
|
deny
}
tcp
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
[
control-flag
control-flags
flag-bitmask
]
protocol-number
– A specific protocol number. (Range: 0-255)
source
– Source IP address.
destination
– Destination IP address.
address-bitmask
– Decimal number representing the address bits to
match.
host
– Keyword followed by a specific IP address.
precedence
– IP precedence level. (Range: 0-7)
tos
– Type of Service level. (Range: 0-15)
dscp
– DSCP priority level. (Range: 0-63)
sport
– Protocol
17
source port number. (Range: 0-65535)
dport
– Protocol
destination port number. (Range: 0-65535)
17. Includes TCP, UDP or other protocol types.
Summary of Contents for DG-FS4528P
Page 2: ......
Page 4: ......
Page 148: ...CHAPTER 5 Simple Network Management Protocol Configuring SNMPv3 Groups 148 ...
Page 389: ...CHAPTER 17 VoIP Traffic Configuration Configuring Telephony OUI 389 ...
Page 515: ...CHAPTER 22 System Management Commands UPnP 515 TTL 20 Console ...
Page 972: ......
Page 973: ...DG FS4528P ...