Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
400
Step
Command
Description
Raisecom(config-acl-ip-ext)# rule
[
rule-id
] { deny | permit } { tcp |
udp } {
source-ip-address source-ip-
mask
| any } [
source-port
] [ range
minimum source port
maximum source
port
] {
destination-ip-address
destination-ip-mask
| any }
[
destination-port
] [ ack
ack-
value
] [ dscp
dscp-value
] [ fin
fin-value
] [ fragment ] [ precedence
precedence-value
] [ psh
psh-valu
e ]
[ range
minimum source port
maximum
source port
] [ rst
rst-value
] [ syn
syn-value
] [ tos
tos-value
] [ urg
urg-value
] [ ttl
ttl-value
] [ time-
range
time-range-name
]
5
Raisecom(config-acl-mac)#rule [
rule-
id
] { deny | permit } {
source-mac-
address source-mac-mask
| any }
{
destination-mac-address
destination-mac-mask
| any }
[
ethertype {
ethertype
[
ethertype-
mask
] | ip | arp }
] [ svlan
svlanid
] [ cos
cos-value
] [ cvlan
cvlanid
] [ inner-cos
inner-cos
]
[ time-range
time-range-name
]
(Optional) configure the
matching rule for MAC ACL.
6
Raisecom(config-acl-udf)#rule [
rule-
id
] { deny | permit } { ipv4 |
layer2 | l2-head } [
rule-string
rule-mask offset
] [ second
rule-
string rule-mask offset
] [ third
rule-string rule-mask offset
]
[ time-range
time-range-name
]
(Optional) configure the
matching rule for User ACL.