18. Access Lists
324
access-list
Configures an access list to serve as an IPv4 filter. There are two types of access lists that operate
as IPv4 filters. One type is an IPv4 address filter and the other type is an IPv4 packet filter. An IPv4
address filter filters packets based on IPv4 address. An IPv4 packet filter filters based on source
IPv4 address, destination IPv4 address, VLAN ID, user priority, ToS field value, port number, TCP
flag, ICMP type, and ICMP code.
You can use one access list ID and specify multiple filter conditions.
A maximum of 1024 access lists (for IPv4, IPv6, and MAC) can be created per device.
A maximum of 1024 filter condition entries can be created per IPv4 address filter or IPv4 packet
filter.
A maximum of 1024
remark
parameters can be specified for access lists and QoS flow lists per
device.
For details about access lists, see
Number of access lists that can be created
.
If you specify
permit
for the filter action, you can specify parameters for policy-based routing. If
you use access group commands to apply the target access list to an interface, specify the inbound
side of the VLAN interface. [AX3640S] [OS-L3A]
Syntax
To set or change information:
Configuring supplementary information
access-list
<access list number>
remark
<remark>
Configures an IPv4 address filter.
access-list
<access list number>
[
<sequence>
] {deny | permit} {
<ipv4>
[
<ipv4
wildcard>
] | host
<ipv4>
| any}
Configures an IPv4 packet filter.
For AX3640S series switches:
access-list
<access list number>
[
<sequence>
] permit {
<filter-condition>
}
[
<action-specification>
]
access-list
<access list number>
[
<sequence>
] deny {
<filter-condition>
}
For AX3630S series switches:
access-list
<access list number>
[
<sequence>
] {deny | permit} {
<filter-condition>
}
<filter-condition>
•
When the upper-layer protocol is other than TCP, UDP, ICMP, and IGMP
{deny | permit} {ip |
<protocol>
} {
<source ipv4>
<source ipv4 wildcard>
| host
<source ipv4>
| any} {
<destination ipv4>
<destination ipv4 wildcard>
| host
<destination ipv4>
| any} [{[tos
<tos>
] [precedence
<precedence>
] | dscp
<dscp>
}] [vlan
<vlan id>
] [user-priority
<priority>
]
•
When the upper-layer protocol is TCP
{deny | permit} tcp {
<source ipv4>
<source ipv4 wildcard>
| host
<source ipv4>
|
any}[{eq
<source port>
| range
<source port start>
<source port end>
}]
{
<destination ipv4>
<destination ipv4 wildcard>
| host
<destination ipv4>
| any}
[{eq
<destination port>
| range
<destination port start>
<destination port end>
}]
[ack] [fin] [psh] [rst] [syn] [urg] [{[tos
<tos>
] [precedence
<precedence>
] | dscp
Содержание AX3630S
Страница 1: ...AX3640S AX3630S Software Manual Configuration Command Reference Vol 1 For Version 11 7 AX36S S004X F0...
Страница 16: ......
Страница 43: ...15 Chapter 3 Editing and Working with Configurations end quit exit save write show status top...
Страница 59: ...4 Login Security and RADIUS or TACACS 31 tacacs server...
Страница 63: ...4 Login Security and RADIUS or TACACS 35 aaa authentication login end by reject...
Страница 77: ...4 Login Security and RADIUS or TACACS 49 ip access group ipv6 access list...
Страница 92: ......
Страница 95: ...5 Time Settings and NTP 67 Notes None Related commands set clock show clock show logging...
Страница 100: ...5 Time Settings and NTP 72 ntp master ntp authenticate ntp trusted key ntp broadcast client...
Страница 125: ...7 Device Management 97 Notes None Related commands None...
Страница 129: ...101 Chapter 8 Power Saving Functionality schedule power control shutdown schedule power control time range...
Страница 164: ......
Страница 170: ...10 Link Aggregation 142 channel group mode channel group lacp system priority lacp system priority...
Страница 178: ...10 Link Aggregation 150 channel group max active port...
Страница 183: ...155 PART 4 Layer 2 Switching Chapter 11 MAC Address Table mac address table aging time mac address table static...
Страница 194: ...12 VLAN 166 Related commands mac based vlan static only...
Страница 217: ...12 VLAN 189 Related commands None...
Страница 224: ...12 VLAN 196 Related commands vlan mac...
Страница 240: ...13 Spanning Tree Protocol 212 spanning tree single mode...
Страница 262: ...13 Spanning Tree Protocol 234 spanning tree pathcost method spanning tree single pathcost method...
Страница 276: ...13 Spanning Tree Protocol 248 Related commands None...
Страница 285: ...13 Spanning Tree Protocol 257 Related commands None...
Страница 287: ...13 Spanning Tree Protocol 259 spanning tree vlan mode...
Страница 288: ......
Страница 292: ...14 Ring Protocol 264 Related commands vlan...
Страница 318: ......
Страница 324: ...15 IGMP Snooping 296 Related commands ip igmp snooping...
Страница 326: ......
Страница 331: ...16 MLD Snooping 303 Related commands ipv6 mld snooping...
Страница 340: ......
Страница 385: ...18 Access Lists 357 Notes None Related commands access list ip access list standard ip access list extended...
Страница 389: ...18 Access Lists 361 remark...
Страница 391: ...18 Access Lists 363 Related commands ipv6 access list...
Страница 400: ...18 Access Lists 372 Related commands mac access list extended...
Страница 420: ......
Страница 436: ...19 QoS 408 Related commands ip qos flow list...
Страница 442: ...19 QoS 414 Related commands ipv6 qos flow list...
Страница 449: ...19 QoS 421 Related commands mac qos flow list...
Страница 475: ...19 QoS 447 Related commands mac qos flow list mac qos flow group mac qos flow list resequence remark...
Страница 484: ......
Страница 509: ...21 IEEE802 1X 481 dot1x multiple authentication...
Страница 519: ...21 IEEE802 1X 491 dot1x system auth control dot1x port control...
Страница 534: ...21 IEEE802 1X 506 dot1x system auth control dot1x vlan dynamic enable...
Страница 543: ...21 IEEE802 1X 515 Related commands dot1x system auth control dot1x vlan timeout supp timeout dot1x vlan enable...
Страница 547: ...21 IEEE802 1X 519 dot1x vlan enable...
Страница 551: ...21 IEEE802 1X 523 Related commands dot1x system auth control dot1x vlan enable...
Страница 555: ...21 IEEE802 1X 527 Related commands dot1x system auth control dot1x vlan enable...
Страница 557: ...21 IEEE802 1X 529 Related commands dot1x system auth control dot1x vlan max req dot1x vlan enable...
Страница 560: ......
Страница 592: ......
Страница 598: ...23 MAC based Authentication 570 mac authentication port...
Страница 604: ...23 MAC based Authentication 576 Related commands mac authentication system auth control mac authentication port...
Страница 615: ...24 Authentication VLANs OP VAA 587 fense vlan...
Страница 617: ...24 Authentication VLANs OP VAA 589 be set Related commands fense vaa name fense server fense vlan...
Страница 626: ......
Страница 638: ...25 DHCP Snooping 610 ip dhcp snooping vlan...
Страница 650: ...25 DHCP Snooping 622 ip dhcp snooping ip dhcp snooping trust ip dhcp snooping vlan ip source binding...
Страница 651: ...623 PART 10 High Reliability Based on Redundant Configurations Chapter 26 Power Supply Redundancy power redundancy mode...
Страница 678: ...28 VRRP 650 track interface track ip route vrrp ip vrrp track...
Страница 680: ...28 VRRP 652 ip address track interface track ip route vrrp ip vrrp track...
Страница 682: ...28 VRRP 654 track ip route vrrp ip vrrp track...
Страница 684: ...28 VRRP 656 track interface track ip route vrrp ip vrrp track...
Страница 690: ...28 VRRP 662 track ip route vrrp ip vrrp track...
Страница 692: ...28 VRRP 664 track interface track ip route vrrp ip vrrp track...
Страница 717: ...689 Chapter 31 Storm Control storm control...
Страница 739: ...33 CFM 711 ma vlan group...
Страница 743: ...33 CFM 715 Related commands domain name ethernet cfm cc enable ma name ma vlan group...
Страница 763: ...34 SNMP 735 of the operation will not be applied to the configuration Related commands snmp server host rmon alarm...
Страница 790: ......
Страница 793: ...35 Log Data Output Functionality 765 ip domain name ip name server ip domain lookup...
Страница 805: ...35 Log Data Output Functionality 777 Related commands logging host...
Страница 806: ......
Страница 819: ...36 sFlow Statistics 791 Notes None Related commands None...
Страница 828: ......
Страница 829: ...801 Chapter 38 OADP oadp cdp listener oadp enable oadp hold time oadp ignore vlan oadp interval time oadp run...
Страница 836: ......
Страница 837: ...809 PART 14 Port Mirroring Chapter 39 Port Mirroring monitor session...