Command Reference ACL Commands
H
Org Code field
21
V
Sequence number
50
I
Encapsulated data type
24
W
Confirmation field
54
J
IP version number
26
XY
IP header length and
reserved bits
58
K
TOS field
27
Z
Resrved bits and flags bit
59
L
Length of IP packet
28
a
Windows size field
60
M
ID
30
b
Others
62
N
Flags field
32
The offsets of fields in the above table are their offsets in 802.3 data frames of SNAP+tag.
1.2 access-list
Use this command to create an access list to filter data packets. Use the
no
form of this command to
remove the specified access list.
1.
Standard IP access list (1 to 99, 1300 to 1999)
access-list
id
{
deny
|
permit
} {
source source-wildcard
|
host
source
|
any | interface
idx
}
[
time-range
tm-range-name
] [
log
]
2.
Extended IP access list (100 to 199, 2000 to 2699)
access-list
id
{
deny
|
permit
}
protocol
{
source source-wildcard
|
host
source
|
any| interface
idx
}
{
destination
destination-wildcard
|
host
destination
|
any
} [
precedence
precedence
] [
tos
tos
]
[
fragment
] [
range
lower
upper
] [
time-range
time-range-name
] [
log
]
3.
Extended MAC access list (700 to 799)
access-list
id
{
deny
|
permit
} {
any
|
host
source-mac-address
|
source-mac-address mask
} {
any
|
host
destination-mac-address
|
destination-mac-address mask
} [
ethernet-type
][
cos
[
out
][
inner
in
]]
4.
Extended expert access list (2700 to 2899)
access-list
id
{
deny
|
permit
} [
protocol
| [
ethernet-type
][
cos
[
out
][
inner
in
]]] [
VID
[
out
][
inner
in
]]
{
source
source-wildcard
|
host
source
|
any
} {
host
source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} ][
precedence
precedence
] [
tos
tos
] [
fragment
] [
time-range
time-range-name
]
When you select the Ethernet-type field or cos field:
access-list
id
{
deny
|
permit
} {
ethernet-type|
cos
[
out
][
inner
in
]} [
VID
[
out
][
inner
in
]]
{
source
source-wildcard
|
host
source
|
any
} {
host
source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} [
time-range
time-range-name
]
When you select the protocol field:
access-list
id
{deny | permit}
protocol [VID
[
out
][
inne
r
in
]] {
source
source-wildcard
| host
source
|
any
} {
host
source-mac-address
|
any
}{destination
destination-wildcard
|
host
destination
|
any}
{host
destination-mac-address
|
any} [precedence
precedence
] [
tos
tos
]
[fragment]
[
range
lower
upper
]
[time-range
time-range-name
]
Extended expert ACLs of some important protocols:
Internet Control Message Protocol
(ICMP)
access-list
id
{
deny
|
permit
}
icmp
[
VID
[
out
][
inner
in
]] {
source
source-wildcard
|
host
source
|
any
}
{
host
source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
Summary of Contents for RG-S29 Series
Page 1: ...RG S29 Series Switch RGOS Command Reference Release 11 4 1 B12...
Page 10: ...Command Reference Command Line Interface Commands Platform Description N A...
Page 93: ...Command Reference Line Commands Description...
Page 248: ...Command Reference PKG_MGMT Commands...
Page 332: ...Command Reference Protocol VLAN Commands Commands N A N A Platform Description...
Page 350: ...Command Reference Voice VLAN Commands Description...
Page 430: ...Command Reference LLDP Commands Description...
Page 467: ...Command Reference ERPS Commands Commands N A N A Platform Description N A...
Page 541: ...Command Reference IPv6 Commands Platform Description N A...
Page 914: ...Multicast Commands 1 IPv4 Multicast Routing Commands 2 IGMP Snooping Commands...
Page 1092: ...Configuration Guide SCC Commands Platforms N A...
Page 1196: ...Configuration Guide IPv6 Source Guard Commands Platform Description N A...
Page 1290: ...ACL QoS Configuration Commands 1 ACL Commands 2 QoS Commands...