C613-50170-01 Rev B
Command Reference for x510 Series
1479
AlliedWare Plus™ Operating System - Version 5.4.7-1.x
IP
V
4 H
ARDWARE
A
CCESS
C
ONTROL
L
IST
(ACL) C
OMMANDS
ACCESS
-
LIST
(
NUMBERED
HARDWARE
ACL
FOR
IP
PROTOCOLS
)
Mode
Global Configuration
Default
On an interface controlled by a hardware ACL, any traffic that does not explicitly
match a filter is permitted.
Usage
This command creates an ACL for use with hardware classification. Once you have
configured the ACL, use the
command to
apply this ACL to a port, VLAN or QoS class-map.
ACLs numbered in the range 3000-3699 match on packets that have the specified
source and destination IP addresses.
You can use ACLs to redirect packets, by sending them to the CPU, the mirror port,
or a specific VLAN on a specific port. Use such ACLs with caution. They could
prevent control packets from reaching the correct destination, such as EPSR
healthcheck messages and VCStack messages.
Hardware ACLs will
permit
access unless
explicitly denied
by an ACL action.
Examples
To create an access-list that will deny all IGMP packets (IP protocol 2) from the
192.168.0.0 network, enter the commands:
awplus#
configure terminal
awplus(config)#
access-list 3000 deny proto 2 192.168.0.0/16
any
To destroy the access-list with an access-list identity of 3000 enter the following
commands:
awplus#
configure terminal
awplus(config)#
no access-list 3000
Related
Commands
show access-list (IPv4 Hardware ACLs)
Command
changes
Version 5.4.6-2.1:
send-to-vlan-port
action parameter added
137
MPLS-in-IP / RFC4023
138
MANET Protocols / RFC-ietf-manet-iana-07.txt
139-252
Unassigned / IANA
253
Use for experimentation and testing / RFC3692
254
Use for experimentation and testing / RFC3692
255
Reserved / IANA
Table 36-4: IP protocol number and description (cont.)
Protocol Number
Protocol Description [RFC]