Chapter 25: Access Control Lists
IPv4 ACLs
– 901 –
Console(config-ext-acl)#permit 192.168.1.0 255.255.255.0 any destination-port
80
Console(config-ext-acl)#
This permits all TCP packets from class C addresses 192.168.1.0 with the
TCP control code set to “SYN.”
Console(config-ext-acl)#permit tcp 192.168.1.0 255.255.255.0 any control-
flag 2 2
Console(config-ext-acl)#
R
ELATED
C
OMMANDS
ip access-group
(Interface Configuration)
This command binds an IPv4 ACL to a port. Use the
no
form to remove the
port.
S
YNTAX
ip access-group acl-name
in
[
time-range
time-range-name
] [
counter
]
no ip access-group acl-name
in
acl-name
– Name of the ACL. (Maximum length: 32 characters)
in
– Indicates that this list applies to ingress packets.
time-range-name
- Name of the time range.
(Range: 1-16 characters)
counter
– Enables counter for ACL statistics.
D
EFAULT
S
ETTING
None
C
OMMAND
M
ODE
Interface Configuration (Ethernet)
C
OMMAND
U
SAGE
•
Only one ACL can be bound to a port.
•
If an ACL is already bound to a port and you bind a different ACL to it,
the switch will replace the old binding with the new one.
E
XAMPLE
Console(config)#int eth 1/2
Console(config-if)#ip access-group david in
Console(config-if)#
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...