958
ExtremeWare 7.7 Command Reference Guide
Security Commands
create access-list
create access-list <name> access-mask <access-mask name> {code-point
<code_point>} {dest-mac <dest_mac} {source-mac <src_mac>} {vlan <name>}
{ethertype [IP | ARP | <hex_value>]} {tos <ip_precedence> | {ip-protocol
[tcp | udp | icmp | igmp | <prococol_num>]} {igmp-type [membership-query |
leave-group | v1-membership-report | v2-membership-report | <number> |
any]} {ipmc-group <multicast IP address>/<mask length>} {dest-ip
<dest_IP>/<masklength>} {dest-L4port <dest_port>} {source-ip <src_IP>/<mask
length>} {source-L4port <src_port> [permit {qosprofile <qosprofile>} {set
code-point <code_point>} {set dot1p <dot1p_value} | permit-established
|deny]{vlan-pri}{vlan-pri-2bits}
Description
Creates an access list on an “e” series switch.
NOTE
This command is available only on the “e” series switches. To create access lists for “i” series switches,
use the following five commands:
create access-list icmp destination source
create access-list ip destination source ports
create access-list tcp destination source ports
create access-list udp destination source ports
create access-list igmp destination source igmp-type ipmc-group ports
Syntax Description
name
Specifies the name of the access list.
access-mask
Specifies the name of the associated access mask.
code-point
Specifies a 6-bit DiffServ code point. Valid entries are from 0 to 63.
dest-mac
Specifies the destination MAC address.
source-mac
Specifies the source MAC address.
vlan
Specifies the VLANid.
ethertype
Specifies the Ethernet type field, either IP or ARP.
tos
Specifies a 3-bit precedence field within the IP ToS field. Valid entries are from 0 to 7.
ip-protocol
Specifies the IP protocol by name (UDP, ICMP, OR IGMP) or by protocol-number.
igmp-type
Specifies the IGMP type. The IGMP type can be membership-query, leave-group, or
v1-membership-report length; or a number between 0 and 255.
ipmc-group/<mask length> Specifies the IP multicast group and the mask.
dest-ip
Specifies the destination IP address.
dest-L4port
Specifies the destination TCP/UDP port.
source-ip
Specifies the source IP address.
source-L4port
Specifies the source TCP/UDP port.
set code-point
Specifies a 6-bit DiffServ code point. Valid entries are from 0 to 63.
set dot1p
Specifies the priorities for 802.1p.
permit-established
Specifies to deny any new TCP session initiation.
Summary of Contents for ExtremeWare 7.7
Page 60: ...60 ExtremeWare 7 7 Command Reference Guide Contents ...
Page 72: ...72 ExtremeWare 7 7 Command Reference Guide Command Reference Overview ...
Page 404: ...404 ExtremeWare 7 7 Command Reference Guide VLAN Commands ...
Page 472: ...472 ExtremeWare 7 7 Command Reference Guide QoS Commands ...
Page 492: ...492 ExtremeWare 7 7 Command Reference Guide NAT Commands ...
Page 890: ...890 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Page 1130: ...1130 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Page 1164: ...1164 ExtremeWare 7 7 Command Reference Guide Configuration and Image Commands ...
Page 1436: ...1436 ExtremeWare 7 7 Command Reference Guide Wireless Commands ...
Page 1490: ...1490 ExtremeWare 7 7 Command Reference Guide EAPS Commands ...
Page 1576: ...1576 ExtremeWare 7 7 Command Reference Guide ESRP Commands ...
Page 1774: ...1774 ExtremeWare 7 7 Command Reference Guide IP Unicast Commands ...
Page 1914: ...1914 ExtremeWare 7 7 Command Reference Guide IGP Commands ...
Page 2000: ...2000 ExtremeWare 7 7 Command Reference Guide BGP Commands i Series Switches Only ...
Page 2140: ...2140 ExtremeWare 7 7 Command Reference Guide IPX Commands i Series Platforms Only ...
Page 2156: ...2156 ExtremeWare 7 7 Command Reference Guide ARM Commands BlackDiamond Switch Only ...
Page 2168: ...2168 ExtremeWare 7 7 Command Reference Guide Remote Connect Commands ...
Page 2346: ...2346 ExtremeWare 7 7 Command Reference Guide PoS Commands BlackDiamond Switch Only ...
Page 2446: ...2446 ExtremeWare 7 7 Command Reference Guide LLDP Commands ...
Page 2496: ...2496 ExtremeWare 7 7 Command Reference Guide H VPLS Commands BlackDiamond Switch Only ...
Page 2620: ...2620 ExtremeWare 7 7 Command Reference Guide Index of Commands ...