
C
HAPTER
23
| ACL Commands
– 326 –
acl add
This command adds or modifies an access control entry.
S
YNTAX
acl add
[
ace-id
] [
ace-id-next
]
[
switch
| (
port
port
) | (
policy
policy
)]
[
vlan-id
] [
tag-priority
] [
dmac-type
]
[(
etype
[
ethernet-type
] [
smac
] [
dmac
]) |
(
arp
[
sip
] [
dip
] [
smac
] [
arp-opcode
] [
arp-flags
]) |
(
ip
[
sip
] [
dip
] [
protocol
] [
ip-flags
]) |
(
icmp
[
sip
] [
dip
] [
icmp-type
] [
icmp-code
] [
ip-flags
]) |
(
udp
[
sip
] [
dip
] [
sport
] [
dport
] [
ip-flags
]) |
(
tcp
[
sip
] [
dip
] [
sport
] [
dport
] [
ip-flags
] [
tcp-flags
])]
[
permit
|
deny
] [
rate-limiter
] [
port-copy
] [
logging
] [
shutdown
]
ace-id
- An ACL entry which specifies one of the following criteria to
be matched in the ingress frame. (Range: 1-128; Default: Next
available ID)
ace-id-next
- Inserts the ACE before this row. If not specified, the
ACE is inserted at the bottom of the list. (Range: 1-128)
switch
- ACE applies to all ports on the switch.
port
port
- ACE applies to specified port or a range of ports.
(Range: 1-28)
policy
policy
- An ACL policy identifier to which this ACE is
assigned. (Range: 1-8)
vlan-id
- The VLAN to filter for this rule. (Range: 1-4095, or
any
)
tag-priority
- Specifies the User Priority value found in the VLAN tag
(3 bits as defined by IEEE 802.1p) to match for this rule. (Range: 0-
7, or
any
)
dmac-type
- The type of destination MAC address. (Options:
any
,
unicast
,
multicast
,
broadcast
; Default:
any
)
etype
- One of the following Ethernet or MAC parameters:
ethernet-type
- This option can only be used to filter Ethernet II
formatted packets. (Range: 0x600-0xffff hex, or
any
; Default:
any
)
A detailed listing of Ethernet protocol types can be found in RFC
1060. A few of the more common types include 0800 (IP), 0806
(ARP), 8137 (IPX).
smac
- Source MAC address (xx-xx-xx-xx-xx-xx) or
any
.
dmac
- Destination MAC address (xx-xx-xx-xx-xx-xx) or
any
.
arp
-
One of the following MAC or ARP parameters:
sip
- Source IP address (a.b.c.d/n) or
any
.
dip
- Destination IP address (a.b.c.d/n) or
any
.
smac
- Source MAC address (xx-xx-xx-xx-xx-xx) or
any
.
arp-opcode
- Specifies the type of ARP packet. (Options:
any
-
no ARP/RARP opcode flag is specified,
arp
- frame must have
Summary of Contents for ES4528V-38
Page 1: ...Management Guide www edge core com 28 Port Gigabit Ethernet Switch...
Page 2: ......
Page 4: ......
Page 6: ...ABOUT THIS GUIDE 6...
Page 22: ...FIGURES 22...
Page 26: ...SECTION Getting Started 26...
Page 46: ...CHAPTER 2 Initial Switch Configuration Managing System Files 46...
Page 48: ...SECTION Web Configuration 48...
Page 75: ...CHAPTER 4 Configuring the Switch Creating Trunk Groups 75 Figure 11 LACP Port Configuration...
Page 186: ...CHAPTER 6 Performing Basic Diagnostics Running Cable Diagnostics 186...
Page 192: ...CHAPTER 7 Performing System Maintenance Managing Configuration Files 192...
Page 242: ...CHAPTER 12 Port Commands 242...
Page 248: ...CHAPTER 13 Link Aggregation Commands 248...
Page 266: ...CHAPTER 15 RSTP Commands 266...
Page 276: ...CHAPTER 16 IEEE 802 1X Commands 276...
Page 286: ...CHAPTER 17 IGMP Commands 286...
Page 294: ...CHAPTER 18 LLDP Commands 294...
Page 300: ...CHAPTER 19 MAC Commands 300...
Page 310: ...CHAPTER 21 PVLAN Commands 310...
Page 322: ...CHAPTER 22 QoS Commands 322...
Page 356: ...CHAPTER 26 SNMP Commands 356...
Page 359: ...CHAPTER 27 HTTPS Commands 359 EXAMPLE HTTPS redirect enable HTTPS...
Page 360: ...CHAPTER 27 HTTPS Commands 360...
Page 366: ...CHAPTER 29 UPnP Commands 366...
Page 374: ...CHAPTER 31 Firmware Commands 374...
Page 376: ...SECTION Appendices 376...
Page 390: ...GLOSSARY 390...
Page 395: ......