CLI Reference Guide
ACL Configuration Commands
D
VLAN tag field
14
R
Source IP address
38
E
DSAP (Destination Service
Access Point) field
18
S
Destination IP address
42
F
SSAP (Source Service Access
Point) field
19
T
TCP soure port
46
G
Ctrl field
20
U
TCP destination port
48
H
Org Code field
21
V
Sequence number
50
I
Encapsulated data type
24
W
Confirmation field
54
J
IP version number
26
XY
IP header length and
reserved bits
58
K
TOS field
27
Z
Resrved bits and flags bit
59
L
Length of IP packet
28
a
Windows size field
60
M
ID
30
b
Others
62
N
Flags field
32
The offsets of fields in the above table are their offsets in 802.3 data frames of SNAP+tag.
access-list
Use this command to create an access list rule to filter data packets. The
no
form of this command
deletes the specified access list entries.
Standard IP access list (1 to 99, 1300 to 1999)
access-list
id
{
deny
|
permit
} {
source source-wildcard
|
host
source
|
any | interface
idx
}
[
time-range
tm-range-name
] [
log
]
Extended IP access list (100 to 199, 2000 to 2699)
access-list
id
{
deny
|
permit
}
protocol
{
source source-wildcard
|
host
source
|
any| interface
idx
}
{
destination
destination-wildcard
|
host
destination
|
any
} [
precedence
precedence
] [
tos
tos
]
[
fragment
] [
range
lower
upper
] [
time-range
time-range-name
] [
log
]
Extended MAC access list (700 to 799)
access-list
id
{
deny
|
permit
} {
any
|
host
source-mac-address
} {
any
|
host
destination-mac-address
} [
ethernet-type
][
cos
[
out
][
inner
in
]]
Extended expert access list (2700 to 2899)
access-list
id
{
deny
|
permit
} [
protocol
| [
ethernet-type
][
cos
[
out
][
inner
in
]]] [
VID
[
out
][
inner
in
]]
{
source
source-wildcard
|
host
source
|
any
} {
host
source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} ][
precedence
precedence
] [
tos
tos
] [
fragment
] [
time-range
time-range-name
]
When you select the Ethernet-type field or cos field:
access-list
id
{
deny
|
permit
} {
ethernet-type|
cos
[
out
][
inner
in
]} [
VID
[
out
][
inner
in
]]
{
source
source-wildcard
|
host
source
|
any
} {
host
source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} [
time-range
time-range-name
]
When you select the protocol field:
access-list
id
{deny | permit}
protocol [VID
[
out
][
inne
r
in
]] {
source
source-wildcard
| host
source
|
any
} {
host
source-mac-address
|
any
}{destination
destination-wildcard
|
host
destination
|
any}
{host
destination-mac-address
|
any} [precedence
precedence
] [
tos
tos
]
[fragment]
[
range
lower
Summary of Contents for RG-S2600G-I Series
Page 1: ...1 CLI Reference Guide RG S2600G I Series Switches RGOS 10 4 3b16...
Page 5: ...5...
Page 505: ...CLI Reference TCP Configuration Commands Related commands Command Description...
Page 514: ...IP Routing Configuration Commands 1 IP Routing Configuration Commands...
Page 642: ...CLI Reference TACACS Configuration Commands host...
Page 652: ...CLI Reference 802 1X Configuration Commands Ruijie config if end...
Page 776: ...CLI Reference ND Snooping Configuration Commands...
Page 901: ...CLI Reference NFPP Configuration Commands...
Page 902: ...ACL QOS Configuration Commands 1 ACL Configuration Commands 2 QoS Configuration Commands...
Page 999: ...CLI Reference RLDP Configuration Command Command mode Privileged EXEC mode...
Page 1005: ...CLI Reference DLDP Configuration Commands...
Page 1191: ...CLI Reference Guide RSPAN Configuration Commands Platform Description N A...
Page 1192: ...CLI Reference Guide...