686
Command Reference for IE200 Series Industrial Managed PoE+ Switches
C613-50066-01 REV A
AlliedWare Plus™ Operating System - Version 5.4.5I-0.x
IP
V
4 H
ARDWARE
A
CCESS
C
ONTROL
L
IST
(ACL) C
OMMANDS
ACCESS
-
LIST
(
HARDWARE
IP
NUMBERED
)
Syntax [proto]
access-list <
3000-3699
> {deny|permit|send-to-cpu} proto
<ip-protocol> <source> <destination>
no access-list <
3000-3699
>
<
destination
>
The destination address of the packets. You can specify a single
host, a subnet, or all destinations. The following are the valid
formats for specifying the destination:
any
Matches any destination IP
address.
host
<ip-addr>
Matches a single destination host
with the IP address given by
<ip-addr>
in dotted decimal
notation.
<
ip-addr
>/<
prefix
>
An IPv4 address, followed by a
forward slash, then the prefix
length. This matches any
destination IP address within the
specified subnet.
<
ip-addr
>
<
reverse-mask
>
Alternatively, you can enter a
reverse mask in dotted decimal
format. For example, entering
192.168.1.1 0.0.0.255
is
the same as entering
192.168.1.1/24
.
<
sourceport
>
The source (TCP or UDP) port number, specified as an integer
between 0 and 65535.
eq
Matches port numbers that are equal to the port number
specified immediately after this parameter.
Table 22-3:
Parameters in the access-list (hardware IP numbered)
command -
tcp|udp (cont.)
Parameter
Description
Table 22-4:
Parameters in the access-list (hardware IP numbered)
command -
proto
Parameter
Description
<
3000-3699
>
Hardware IP access-list.
deny
Access-list rejects packets that match the source and destination
filtering specified with this command.
permit
Access-list permits packets that match the source and
destination filtering specified with this command.
send-to-cpu
Specify packets to send to the CPU.