
Access Control List (ACL) Commands
©2008 Allied Telesis Inc. All rights reserved.
Software Version 5.2.1
AlliedWare Plus
TM
Operating System Software Reference C613-50003-00 REV E
38.7
Syntax
[proto]
access-list <3000-3699>
{copy-to-cpu|copy-to-mirror|deny|permit|send-to-cpu}
{proto <
ip-protocol
>}
{
<source>
|any|host}{
<destination>
|any|host}
no access-list <3000-3699>
Parameter
Description
<3000-3699>
Hardware IP access list
copy-to-cpu
Specify packets to copy to the CPU.
copy-to-mirror
Specify packets to copy to the mirror port.
deny
Access-list rejects packets that match the source and destination filtering
specified with this command.
permit
Access-list permits packets that match the source and destination filtering
specified with this command.
send-to-cpu
Specify packets to send to the CPU.
<source>
The source address of the packets. You can specify either a subnet, a host,
or all sources. The following are the valid formats to specify the source:
any
Filters packets with any source address.
host
<ip-addr>
Filters packets matching a specific source address.
<ip-addr>/
<reverse-mask>
Filters packets from the network specified by an IP
address and wildcard mask. The IP address and mask
are specified in dotted decimal notation with a space
between the IP address and the mask. The mask
works as a reverse address mask. For example,
0.0.0.255 means you permit or deny the route which
matches the first 24 bits, A.B.C.D.
any
Any source host.
host
A single source host.
<destination>
The destination of the packets. You can specify either a subnet, a host, or
all destinations. The following are valid formats to specify the destination:
any
Filters packets with any destination address.
host
<ip-addr>
Filters packets matching a specific destination address.
<ip-addr/
reverse-mask>
Filters packets from the network specified by an IP
address and wildcard mask. The IP address and mask
are specified in dotted decimal notation with a space
between the IP address and the mask. The mask
works as a reverse address mask. For example,
0.0.0.255 means you permit or deny the route which
matches the first 24 bits, A.B.C.D.
proto
Matches only a specified type of ICMP messages. This is valid only when the
filtering is set to match ICMP packets.
<ip-protocol>
<1-255>
The IP protocol number, as defined by IANA (Internet Assigned Numbers
Authority www.iana.org ref: www.iana.org/assignments/protocol-numbers)
Protocol Number
Protocol Description [RFC Reference]
1
Internet Control Message [RFC792]
2
Internet Group Management [RFC1112]
3
Gateway-to-Gateway [RFC823]
Содержание AlliedWare Plus 5.2.1
Страница 8: ...65 Stacking Commands Introduction 65 2 Appendix l Command List ...
Страница 10: ......
Страница 218: ......
Страница 376: ......
Страница 726: ......
Страница 806: ......
Страница 1006: ......
Страница 1056: ......
Страница 1235: ...Stacking Reference This part includes the following chapters Chapter 64 Stacking Introduction Chapter 65 Stacking Commands ...
Страница 1236: ......