
Chapter 9
| Access Control Lists
IPv4 ACLs
– 338 –
permit, deny
(Extended IPv4 ACL)
This command adds a rule to an Extended IPv4 ACL. The rule sets a filter condition
for packets with specific source or destination IP addresses, protocol types, source
or destination protocol ports, or TCP control codes. Use the
no
form to remove a
rule.
Syntax
{
permit
|
deny
} [
protocol
-
number |
udp
]
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
[
time-range
time-range-name
]
no
{
permit
|
deny
} [
protocol
-
number |
udp
]
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
{
permit
|
deny
}
tcp
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
[
control-flag
control-flags
flag-bitmask
]
[
time-range
time-range-name
]
no
{
permit
|
deny
}
tcp
{
any
|
source address-bitmask |
host
source
}
{
any
|
destination address-bitmask |
host
destination
}
[
precedence
precedence
] [
tos
tos
] [
dscp
dscp
]
[
source-port
sport
[
bitmask
]]
[
destination-port
dport
[
port
-
bitmask
]]
[
control-flag
control-flags
flag-bitmask
]
protocol-number
– A specific protocol number. (Range: 0-255)
source
– Source IP address.
destination
– Destination IP address.
address-bitmask
– Decimal number representing the address bits to match.
host
– Keyword followed by a specific IP address.
precedence
– IP precedence level. (Range: 0-7)
tos
– Type of Service level. (Range: 0-15)
dscp
– DSCP priority level. (Range: 0-63)
sport
– Protocol
3
source port number. (Range: 0-65535)
3. Includes TCP, UDP or other protocol types.
Summary of Contents for AS5700-54X
Page 42: ...Contents 42...
Page 44: ...Figures 44...
Page 52: ...Tables 52...
Page 54: ...Section I Getting Started 54...
Page 80: ...Chapter 1 Initial Switch Configuration Setting the System Clock 80...
Page 210: ...Chapter 6 Remote Monitoring Commands 210...
Page 358: ...Chapter 9 Access Control Lists ACL Information 358...
Page 418: ...Chapter 12 Port Mirroring Commands RSPAN Mirroring Commands 418...
Page 436: ...Chapter 15 UniDirectional Link Detection Commands 436...
Page 442: ...Chapter 16 Address Table Commands 442...
Page 506: ...Chapter 18 VLAN Commands Configuring VXLAN Tunneling 506...
Page 526: ...Chapter 19 Class of Service Commands Priority Commands Layer 3 and 4 526...
Page 544: ...Chapter 20 Quality of Service Commands 544...
Page 652: ...Chapter 22 Multicast Filtering Commands MLD Proxy Routing 652...
Page 680: ...Chapter 23 LLDP Commands 680...
Page 722: ...Chapter 24 CFM Commands Delay Measure Operations 722...
Page 732: ...Chapter 25 Domain Name Service Commands 732...
Page 790: ...Chapter 27 IP Interface Commands ND Snooping 790...
Page 1072: ...Section III Appendices 1072...
Page 1102: ...List of CLI Commands 1102...
Page 1115: ......
Page 1116: ...AS5700 54X AS6700 32X E032016 ST R02 149100000198A...