
Access Control List Configuration
165
list offline within a configuration file and downloading the configuration file later via TFTP to your
SmartNode device.
19.4 Create an Access Control List Profile and Enter
Configuration Mode
Procedure
To create an IP access control list and enter access control list configuration mode
Mode
Administrator execution
Command Purpose
Step 1
node
(cfg)#profile acl
name
Creates the access control list profile
name
and enters the configuration mode for
this list
name
is the name by which the access list will be known. Entering this command puts you into
access
control list configuration mode
where you can enter the individual statements that will make up the
access control list.
Use the
no
form of this command to delete an access control list profile. You cannot delete an access
control list profile if it is currently linked to an interface. When you leave the access control list
configuration mode, the new settings immediately become active.
Example: Create an Access Control List Profile
In the following example the access control list profile named WanRx is created and the shell of the
access control list configuration mode is activated.
SN>
enable
SN#
configure
SN(cfg)#
profile acl WanRx
SN(pf-acl)[WanRx]#
19.5 Add a Filter Rule to the Current Access Control List
Profile
The commands
permit
or
deny
are used to define an IP filter rule.
Procedure
To create an IP access control list entry that
permits access
Mode
Profile access control list
Command
Purpose
Step 1
node
(pf-acl)[
name
]#permit ip
{
src
src-wildcard
|
any
|
host
src
} {
dest
dest-wildcard
|
any
|
host
dest
} [
cos
group
]
Creates an IP access of control list
entry that permits access defined
according to the command options
Procedure
Software Configuration Guide, Revision 1.03
To create an IP access control list entry that
denies access
Summary of Contents for SmartWare R2.00
Page 2: ......