IPv4 Access Control Lists (ACLs)
Overview of Options for Applying IPv4 ACLs on the Switch
Create a Standard,
ProCurve(config)# access-list < 1-99 > < deny | permit >
Numbered
ACL
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
or
[log]
2
Add an ACE to the End
of an Existing
Standard,
Numbered
ACL
Use a Sequence
ProCurve(config)# ip access-list standard <
name-str
| 1-99 >
Number To Insert an
ProCurve(config-std-nacl)# 1-2147483647 < deny | permit >
ACE in a Standard ACL
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
1
[log]
2
Use an ACE’s
ProCurve(config)# ip access-list standard <
name-str
| 1-99 >
Sequence Number To
ProCurve(config-std-nacl)# no < 1-2147483647 >
Delete the ACE from a
Standard ACL
Resequence the ACEs
ProCurve(config)# ip access-list resequence <
name-str
| 1-99 > < 1-2147483647 >
in a Standard ACL
< 1-2147483646 >
Enter or Remove a
ProCurve(config)# ip access-list standard <
name-str
| 1-99 >
Remark from a
ProCurve(config-ext-nacl)# [ remark <
remark-str
> | no < 1-2147483647 > remark ]
Standard ACL
For numbered, standard ACLs only, the following
remark
commands can be
substituted for the above:
ProCurve(config)# access-list < 1 - 99 > remark < remark-str >
ProCurve(config)# [no] access-list < 1 - 99 > remark
Delete a Standard ACL
ProCurve(config)# no ip access-list standard <
name-str
| 1-99 >
For numbered, standard ACLs, the following command can be substituted for the
above:
ProCurve(config)# access-list < 1 - 99 > remark < remark-str >
1
The mask can be in either dotted-decimal notation (such as 0.0.15.255) or CIDR notation (such as /20).
2
The [ log ] function applies only to “deny” ACLs, and generates a message only when there is a “deny” match.
9-7
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......