773
Switch(Config-MacIp-Ext-Nacl-macip_acl)#
19.2.2.19 permit | deny( ip extended)
Command: [no] {deny | permit} icmp {{<sIpAddr> <sMask>} | any | {host
<sIpAddr>}} {{<dIpAddr>
<dMask>} | any-destination | {host-destination
<dIpAddr>}} [<icmp-type>
[<icmp-code>]] [precedence <prec>] [tos
<tos>][time-range<time-range-name>]
[no] {deny | permit} igmp {{<sIpAddr> <sMask>} | any | {host <sIpAddr>}}
{{<dIpAddr>
<dMask>} | any-destination | {host-destination <dIpAddr>}}
[<igmp-type>] [precedence <prec>] [tos <tos>][time-range<time-range-name>]
[no] {deny | permit} tcp {{<sIpAddr> <sMask>} | any | {host <sIpAddr>}}
[s-port <sPort>] {{<dIpAddr> <dMask>} | any-destination | {host-destination
<dIpAddr>}} [d-port <dPort>] [ack+fin+psh+rst+urg+syn] [precedence <prec>] [tos
<tos>][time-range<time-range-name>]
[no] {deny | permit} udp {{<sIpAddr> <sMask>} | any | {host <sIpAddr>}}
[s-port <sPort>] {{<dIpAddr> <dMask>} | any-destination | {host-destination
<dIpAddr>}}[d-port<dPort>][precedence<prec>[tos<tos>][time-range<time-range-n
ame>]
[no] {deny | permit} {eigrp | gre | igrp | ipinip | ip | <int>} {{<sIpAddr>
<sMask>} | any | {host <sIpAddr>}} {{<dIpAddr> <dMask>} | any-destination |
{host-destination<dIpAddr>}}[precedence<prec>][tos<tos>][time-range<time-range
-name>]
Functions:
Create a name extended IP access rule to match specific IP protocol or all IP
protocol;
Parameters: <sIpAddr>
is the source IP address, the format is dotted decimal notation;
<sMask >
is the reverse mask of source IP, the format is dotted decimal notation;
<dIpAddr>
is the destination IP address, the format is dotted decimal notation;
<dMask>
is the reverse mask of destination IP, the format is dotted decimal notation, attentive
position o, ignored position 1;
<igmp-type>
, the type of igmp, 0-15;
<icmp-type>
, the
type of icmp, 0-255 ;
<icmp-code>,
protocol No. of icmp, 0-255;
<prec>
, IP priority, 0-7;
<tos>
, to value, 0-15;
<sPort>
, source port No., 0-65535;
<dPort>
, destination port No.
0-65535;
<time-range-name>
, time range name
Command Mode:
Name extended IP access-list configuration mode
Default:
No access-list configured
Examples:
Create the extended access-list, deny icmp packet to pass, and permit udp
packet with destination address 192. 168. 0. 1 and destination port 32 to pass.
Switch(Config)# access-list ip extended udpFlow
Switch(Config-Ext-Nacl-udpFlow)# deny igmp any any-destination