172
Access Control List Configuration
Software Configuration Guide, Revision 1.03
19.9 Display an Access Control List Profile
The
show profile acl
command displays the indicated access control list profile. If no specific profile
is selected all installed access control list profiles are shown. If an access control list is linked to an IP
interface the number of matches for each rule is displayed. If the access control list profile is linked to
more than one IP interface, it will be shown for each interface.
Procedure
To display a certain access control list profile
Mode
Administrator execution or any other mode, except the operator execution mode
Command Purpose
Step 1
node
#show profile acl
name
Displays the access control list
profile
name
Example: Displaying an Access Control List Entries
The following example shows how to display the access control list profile named WanRx.
SN#
show profile acl WanRx
IP access-list WanRx. Linked to router/wan/in.
deny icmp any any msg echo
permit ip 62.1.2.3 0.0.255.255 host 193.14.2.11
permit ip 97.123.111.0 0.0.0.255 host 193.14.2.11
permit tcp any host 193.14.2.10 eq 80
permit udp host 62.1.2.3 host 193.14.2.11 range 1024 2048
deny ip any any
19.10 Debug an Access Control List Profile
The
debug acl
command is used to debug the access control list profiles during system operation.
Use the
no
form of this command to disable any debug output.
Procedure
To debug the access control list profiles
Mode
Administrator execution or any other mode, except the operator execution
Command Purpose
Step 1
node
#debug acl
Enables access control list debug
monitor
Procedure
To activate the debug level of an access control list profiles for a specific interface.
Mode
Interface
Command Purpose
Step 1
node
(cfg)#context ip router
Selects the IP router context
Summary of Contents for SmartWare R2.00
Page 2: ......