S2600E CLI Reference Guide Chapter 1 ACL Configuration Commands
destination-wildcard
|
host destination
|
any
} {
host destination-mac-address
|
any
} [
precedence
precedence
] [
tos
tos
] [
fragment
] [
range
lower
upper
]
[
time-range time-range-name
]
Extended expert ACLs of some important protocols:
Internet Control Message Protocol
(ICMP)
[
sn
]
deny icmp
[[
VID
[
out
][
inner in
]]] {
source source-wildcard
|
host source
|
any
} {
host source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host destination-mac-address
|
any
} [
icmp-type
]
[[
icmp-type
[
icmp-code
]] | [
icmp-message
]] [
precedence precedence
] [
tos
tos
] [
fragment
] [
time-range
time-range-name
]
Transmission Control Protocol
(TCP)
[
sn
]
deny tcp
[[
VID
[
out
][
inner in
]]]{
source
source-wildcard
|
host
Source
|
any
} {
host source-mac-address
|
any
} [
operator
port
[
port
]] {
destination
destination-wildcard
|
host
destination
|
any
} {
host destination-mac-address
|
any
} [
operator port
[
port
]] [
precedence
precedence
] [
tos tos
] [
fragment
]
[
range
lower
upper
] [
time-range time-range-name
] [
match-all tcp-flag
]
User Datagram Protocol
(UDP)
[
sn
]
deny udp
[[
VID
[
out
][
inner in
]]]{
source source –wildcard
|
host source
|
any
} {
host source-mac-address
|
any
} [
operator
port
[
port
]] {
destination
destination-wildcard
|
host destination
|
any
}{
host
destination-mac-address
|
any
} [
operator port
[
port
]] [
precedence
precedence
] [
tos
tos
] [
fragment
] [
range
lower
upper
] [
time-range
time-range-name
]
Address Resolution Protocol (ARP)
[
sn
]
deny arp
{
vid vlan-id
}[
source-mac-address source-wildcard |host
source-mac-address
|
any
] [
host
destination –mac-address
|
any
]
{
sender-ip sender-ip–wildcard
|
host
sender-ip
|
any
} {
sender-mac
sender-mac-wildcard
|
host
sender-mac
|
any
} {
target-ip target-ip–wildcard
|
host
target-ip
|
any
}
5. Extended IPv6 ACL
[
sn
]
deny protocol
{
source-ipv6-prefix
/
prefix-length
|
any
|
host
source-ipv6-address
} {
destination-ipv6-prefix / prefix-length
|
any
|
hostdestination-ipv6-address
} [
dscp
dscp
] [
flow-label flow-label
] [
fragment
]
[
range
lower
upper
] [
time-range time-range-name
]
Summary of Contents for RG-S2600E Series
Page 1: ...CLI Reference Guide RG S2600E Series Switch RGOS 10 4 3 p1 1...
Page 5: ...Basic Configuration...
Page 83: ...Ethernet Switching...
Page 240: ...IPApplication...
Page 263: ...S2600E P CLI Reference Guide Chapter 1 IP Address Configuration Commands Platform description...
Page 317: ...S2600E P CLI Reference Guide Chapter 5 DHCP Relay Configuration Commands Platform description...
Page 335: ...Network Management and Monitoring...
Page 408: ...S2600E CLI Reference Guide Chapter 5 SPAN Configuration Commands...
Page 415: ...S2600E CLI Reference Guide Chapter 6 RSPAN Configuration Commands Platform description N A...
Page 416: ...Multicast Commands...
Page 449: ...S2600E P CLI Reference Guide Chapter 1 IGMP Snooping Commands Example3 Example4...
Page 450: ...S2600E P CLI Reference Guide Chapter 1 IGMP Snooping Commands...
Page 477: ...Security...
Page 878: ...ACL QOS...
Page 953: ...Reliability...
Page 1024: ...S2600E CLI Reference Guide Chapter 6 GRTD Configuration Commands Platform description...
Page 1031: ...S2600E CLI Reference Guide Chapter 6 GRTD Configuration Commands Platform description...
Page 1035: ...S2600E CLI Reference Guide Chapter 6 GRTD Configuration Commands 6 3 Display Related Commands...
Page 1121: ...System Management...