Security and authentication
11.4 IP access control list
SCALANCE XM-400/XR-500 Command Line Interface (CLI)
Configuration Manual, 06/2016, C79000-G8976-C252-11
851
11.4.4.7
permit udp
Description
With this command, you configure an IP access control list for the UDP protocol.
You have the following options:
●
All incoming and/or outgoing UDP datagrams are forwarded.
●
Incoming and/or outgoing UDP datagrams of a specific host are forwarded.
●
Incoming and/or outgoing UDP datagrams of hosts of a specific subnet are forwarded.
●
Incoming and/or outgoing UDP datagrams are forwarded to specific ports.
Note
Processing order of the lists
The access control lists are processed on the interface in the order in which they were
created.
The index number of the access control list is not used for this.
Requirement
You are in the ACL standard configuration mode.
The command prompt is as follows:
cli(config-std-nacl)#
Syntax
Call up the command with the following parameters:
permit udp {any | host <src-ip-address> | <src-ip-address> <src-mask>} [{ gt <port-
number(1-65535)> | lt <port-number(1-65535)> | eq <port-number(1-65535)> | range
<port-number (1-65535)> <port-number (1-65535)>}] [{any | host <dest-ip-address> |
<dest-ip-address> <dest-mask>}] [{ gt <port-number(1-65535)> | lt <port-number(1-
65535)> | eq <port-number(1-65535)> | range <port-number (1-65535)> <port-number (1-
65535)>}] [dscp<value(0-63)>]
The parameters have the following meaning:
Parameter
Description
Range of values / note
any
Forwards all incoming UDP frames.
-
host
Keyword for a an individual IPv4 ad-
dress
-
src-ip-address
Source IPv4 address
Enter a valid IPv4 address.
src-ip-address
Network source address
Enter a valid combination of IPv4
address and subnet mask.
src-mask
Corresponding subnet mask
Summary of Contents for SCALANCE XM-400
Page 882: ......