14-5
Usage Guidelines
Use this command to deny traffic between network’s/host’s based on the protocol type selected in the access
list configuration. The following protocol types are supported:
•
ip
•
icmp
•
tcp
•
udp
The last ACE in the access list is an implict deny statement.
Whenever the interface receives the packet, its content is checked against the ACE’s in the ACL. It is
allowed/denied based on the ACL configuration.
•
Filtering on protocol types tcp/udp allows the user to specify port numbers as filtering criteria.
deny {
tcp|udp
} {source/
source-mask | host source
| any} [operator source-
port] {destination/
destination-mask | host
destination | any}
[operator destination-port]
[log] [rule-precedence
access-list-entry
precedence]
Use with
deny
command to reject tcp or udp packets.
•
deny – The keyword specifies deny action on an ACL.
•
{
tcp|udp
} – Specify tcp or udp as the protocol.
•
{source/source-mask | host source | any} – The keyword
source
is the
source IP address of the network or host in dotted decimal format.
Source-mask is the network mask. For example, 10.1.1.10/24 indicates
the first 24 bits of the source IP are used for matching.
•
any
is an abbreviation for source IP of 0.0.0.0 and source-mask bits
equal to 0.
•
host
is an abbreviation for exact source (A.B.C.D) and source-mask
bits equal to 32.
•
[operator source-port] – Valid only for tcp or udp protocols. Valid values
are
eq
and
range
.
•
range – Specifies the protocol range (starting and ending protocol
numbers).
•
port – Valid Port number.
•
{destination/destination-mask | host destination | any} – The destination
host IP address or destination network address.
•
[operator destination-port] – Specifies the destination port.
•
[log] – Generates log messages when the packet coming from the
interface matches the ACL entry. Log messages are generated only for
router ACLs.
•
[rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.
Summary of Contents for RFS7000 Series
Page 1: ... RFS7000 Series RF Switch CLI Reference Guide ...
Page 10: ...x RFS7000 Series CLI Reference Guide ...
Page 30: ...Overview 1 10 ...
Page 196: ...Overview 4 46 ...
Page 270: ...Overview 5 74 ...
Page 284: ...Overview 6 14 ...
Page 294: ...Overview 7 10 ...
Page 304: ...Overview 8 10 ...
Page 308: ...Overview 9 4 ...
Page 338: ...Overview 11 36 ...
Page 366: ...Overview 12 28 ...
Page 380: ...Overview 13 14 ...
Page 404: ...Overview 15 2 terminal Sets terminal line parameters page 15 14 Command Description Ref ...
Page 434: ...Overview 16 18 ...
Page 466: ...Overview 17 32 ...
Page 474: ...Overview 18 8 ...
Page 504: ...Overview 19 30 ...
Page 572: ...Overview 20 68 ...
Page 584: ...Overview 21 12 ...
Page 586: ...A 2 RFS7000 Series CLI Reference Guide ...
Page 587: ......