![Intel 480T User Manual Download Page 258](http://html1.mh-extra.com/html/intel/480t/480t_user-manual_2073446258.webp)
256
C H A P T E R 1 4
Access Policies
The
established
Keyword
Access lists support the use of the
established
keyword. This
keyword allows directional control of attempts to open a TCP
session. Sessions can be explicitly permitted in the entry. For
example, the following entry permits TCP sessions originated from
anywhere in the 10.1.0.0 network, only:
create access-list TCPout tcp destination 10.1.0.0/
16 range any source 0.0.0.0/0 range any permit-
established port any
In this example, the
established
keyword allows only TCP
packets with the ACK or RST bit set to destination 10.1.0.0. from
anywhere, but not to any other destination.
Adding and Deleting Access List Entries
You can add and delete entries in the access list. To add an entry,
you must supply a unique name and, optionally, a unique
precedence number. To modify an existing entry, you must delete
the entry and retype it, or create a new entry with a new unique
name.
To delete an access list entry, use the command:
delete access-list <name>
Maximum Entries
You can use up to a maximum of 255 entries with an assigned
precedence. In addition to the 255 entries, you can also create
entries that do not use precedence, with the following restrictions:
•
A source IP address must use wild-cards or be completely
specified (32 bit mask).
•
The layer 4 source and destination ports must use wildcards or be
completely specified (no ranges).
•
No physical source port can be specified.
Access Lists for ICMP
Access lists for ICMP traffic processing are handled in a slightly
different manner. An access list for ICMP is only effective for
traffic routed by the switch. ICMP traffic may either be forwarded
Summary of Contents for 480T
Page 16: ...14 P R E F A C E...
Page 88: ...86 C H A P T E R 4 Configuring Switch Ports...
Page 112: ...110 C H A P T E R 5 Virtual LANs VLANs...
Page 152: ...150 C H A P T E R 8 Quality of Service QoS...
Page 166: ...164 C H A P T E R 9 Enterprise Standby Router Protocol...
Page 198: ...196 C H A P T E R 1 0 IP Unicast Routing...
Page 228: ...226 C H A P T E R 1 1 RIP and OSPF...
Page 254: ...252 C H A P T E R 1 3 IPX Routing...
Page 274: ...272 C H A P T E R 1 4 Access Policies...
Page 296: ...294 C H A P T E R 1 6 Using Web Device Manager...
Page 320: ...318 A P P E N D I X A...
Page 328: ...326 A P P E N D I X B...
Page 346: ...344 A P P E N D I X C...
Page 358: ...356 I N D E X...
Page 366: ...364 I N D E X...