access-list
Syntax
Standard IP access list:
access-list
accessListName
{ permit | deny }
{
srcIP srcWildIp
| [ host ]
srcIPHost
| any } [ log ]
no access-list
accessListName
[ { permit | deny }
{
srcIP srcWildIp
| [ host ]
srcIPHost
| any } [ log ] ]
Extended IP access list:
access-list
accessListName
{ permit | deny } ip {
srcIP srcWildIp
|
host
srcIPHost
| any } {
dstIP dstWildIp
| host
dstIPHost
| any } [ log ]
no access-list
accessListName
[ { permit | deny } ip {
srcIP srcWildIp
|
host
srcIPHost
| any } {
dstIP dstWildIp
| host
dstIPHost
| any } [ log ] ]
Release Information
Command introduced before JUNOSe Release 7.1.0.
Description
Defines a standard or extended IP access list. The extended access list enables you
to specify a destination address or host, precedence, and type of service. This
command imposes an implicit last rule of “ deny ip any any” to deny all routes that
do not match previous rules in the access list. The
no
version removes the IP access
list, the specified entry in an access list, or the log for a specified entry.
Options
■
accessListName
—String of up to 32 alphanumeric characters
■
permit—Permits access if the conditions are matched
■
deny—Denies access if the conditions are matched
■
srcIP—
Source IP address from which the packet is being sent
■
srcWildIp—
Wildcard mask IP address
■
host
—
Identifies the address as a host
■
srcIPHost—
Source host IP address; assumes a wildcard mask of 0
■
any
—
Creates an address of 0.0.0.0 with a wildcard mask of 255.255.255.255
■
dstIP
—Destination IP address
■
dstWildIp
—Wildcard mask IP address for destination
■
dstIPHost
—Destination host IP address to which the packet is being sent
■
log—Logs an Info event into the ipAccessList log whenever the access-list rule is
matched
Mode
Global Configuration
access-list
■
79
Chapter 2: A Commands
Summary of Contents for JUNOSE 11.0
Page 6: ...vi...
Page 8: ...viii JUNOSe 11 0 x Command Reference Guide A to M...
Page 38: ...xxxviii List of Tables JUNOSe 11 0 x Command Reference Guide A to M...
Page 44: ...2 Commands A to M JUNOSe 11 0 x Command Reference Guide A to M...
Page 62: ...20 Interface Types and Specifiers JUNOSe 11 0 x Command Reference Guide A to M...
Page 63: ...Chapter 2 A Commands 21...
Page 185: ...Mode Global Configuration Subscriber Policy Configuration arp 143 Chapter 2 A Commands...
Page 253: ...Chapter 3 B Commands 211...
Page 388: ...346 bundled group id overrides mlppp ed JUNOSe 11 0 x Command Reference Guide A to M...
Page 389: ...Chapter 4 C Commands 347...
Page 515: ...Chapter 5 D Commands 473...
Page 595: ...Chapter 6 E Commands 553...
Page 649: ...Chapter 7 F Commands 607...
Page 687: ...Chapter 8 G Commands 645...
Page 703: ...Chapter 9 H Commands 661...
Page 718: ...676 hotfix activate JUNOSe 11 0 x Command Reference Guide A to M...
Page 719: ...Chapter 10 I Commands 677...
Page 1009: ...Configuring an ICR Partition ip vrrp icr partition vlan range 967 Chapter 10 I Commands...
Page 1168: ...1126 is type JUNOSe 11 0 x Command Reference Guide A to M...
Page 1169: ...Chapter 11 K Commands 1127...
Page 1171: ...Related Topics Configuring RADIUS Based Mirroring key 1129 Chapter 11 K Commands...
Page 1173: ...Chapter 12 L Commands 1131...
Page 1273: ...Mode Global Configuration log severity 1231 Chapter 12 L Commands...
Page 1284: ...1242 lsp refresh interval JUNOSe 11 0 x Command Reference Guide A to M...
Page 1285: ...Chapter 13 M Commands 1243...
Page 1465: ...Part 2 Index Index on page 1425 Index 1423...
Page 1466: ...1424 Index JUNOSe 11 0 x Command Reference Guide A to M...