IPv4 Access Control Lists (ACLs)
Configuring Extended ACLs
If the ACL does not already exist, this command creates the
specified ACL and its first ACE. If the ACL already exists,
the new ACE is appended to the end of the configured list of
explicit ACEs. In the default configuration, the ACEs in an
ACL will automatically be assigned consecutive sequence
numbers in increments of 10 and can be renumbered with
resequence
Note:
To insert a new ACE between two existing ACEs in
an extended, numbered ACL:
a. Use
ip access list extended < 100 - 199 >
to open the
ACL as a named ACL.
b. Enter the desired sequence number along with the
ACE statement you want.
(Refer to the “Numbered ACLs” list item on page 9-42.)
For a match to occur, a packet must have the source and
destination addressing criteria specified in the ACE, as
well as:
• the protocol-specific criteria configured in the ACE,
including any included, optional elements (described
later in this section)
• any (optional) precedence and/or ToS settings
configured in the ACE
< 100-199 >
Specifies the ACL ID number. The switch interprets a
numeric ACL with a value in this range as an extended
ACL.
< deny | permit >
Specifies whether to deny (
drop
) or permit (forward) a packet
that matches the criteria specified in the ACE, as described
below.
9-67
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......