Chapter 25: Access Control Lists
IPv4 ACLs
– 900 –
•
The control-code bitmask is a decimal number (representing an
equivalent bit mask) that is applied to the control code. Enter a decimal
number, where the equivalent binary bit “1” means to match a bit and
“0” means to ignore a bit. The following bits may be specified:
•
1 (fin) – Finish
•
2 (syn) – Synchronize
•
4 (rst) – Reset
•
8 (psh) – Push
•
16 (ack) – Acknowledgement
•
32 (urg) – Urgent pointer
For example, use the code value and mask below to catch packets with
the following flags set:
•
SYN flag valid, use “control-code 2 2”
•
Both SYN and ACK valid, use “control-code 18 18”
•
SYN valid and ACK invalid, use “control-code 2 18”
•
Due to a ASIC limitation, the switch only checks the leftmost six priority
bits. This presents no problem when checking DSCP or IP Precedence
bits, but limits the checking of ToS bits (underlined in the following
example) to the leftmost three bits, ignoring the rightmost fourth bit.
For example, if you configured an access list to deny packets with a ToS
of 7 (000011
1
0), the highlighted bit would be ignored, and the access
list would drop packets with a ToS of both 6 and 7.
E
XAMPLE
This example accepts any incoming packets if the source address is within
subnet 10.7.1.x. For example, if the rule is matched; i.e., the rule
(10.7.1.0 & 255.255.255.0) equals the masked address (10.7.1.2 &
255.255.255.0), the packet passes through.
Console(config-ext-acl)#permit 10.7.1.1 255.255.255.0 any
Console(config-ext-acl)#
This allows TCP packets from class C addresses 192.168.1.0 to any
destination address when set for destination TCP port 80 (i.e., HTTP).
Table 25-3: Priority Bits Processed by Extended IPv4 ACL
DSCP
Precedence
ToS
7
6
5
4
3
2
1
0
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...