ACL Commands
OL-32830-01 Command Line Interface Reference Guide
116
4
deny
igmp {any | source source-wildcard} {any | destination
destination-wildcard}[igmp-type][
ace-priority
priority] [dscp number | precedence
number] [
time-range
time-range-name] [disable-port |log-input ]
deny tcp
{any | source source-wildcard} {any|source-port/port-range}{any |
destination destination-wildcard} {any|destination-port/port-range} [
ace-priority
priority] [dscp number | precedence number] [match-all list-of-flags][
time-range
time-range-name] [disable-port |log-input ]
deny udp
{any | source source-wildcard} {any|source-port/port-range} {any |
destination destination-wildcard} {any|destination-port/port-range} [
ace-priority
priority] [dscp number | precedence number] [
time-range
time-range-name]
[disable-port |log-input ]
no deny
protocol {any | source source-wildcard} {any | destination
destination-wildcard} [dscp number | precedence number] [
time-range
time-range-name] [disable-port |log-input ]
no deny
icmp {any | source source-wildcard} {any | destination
destination-wildcard} [any | icmp-type] [any | icmp-code]] [dscp number |
precedence number][
time-range
time-range-name] [disable-port |log-input ]
no deny
igmp {any | source source-wildcard} {any | destination
destination-wildcard}[igmp-type] [dscp number | precedence number] [
time-range
time-range-name] [disable-port |log-input ]
no deny tcp
{any | source source-wildcard} {any|source-port/port-range}{any |
destination destination-wildcard} {any|destination-port/port-range} [dscp number |
precedence number] [match-all list-of-flags] [
time-range
time-range-name]
[disable-port |log-input ]
no deny udp
{any | source source-wildcard} {any|source-port/port-range} {any |
destination destination-wildcard} {any|destination-port/port-range} [dscp number |
precedence number] [
time-range
time-range-name] [disable-port |log-input ]
Parameters
•
protocol—The name or the number of an IP protocol. Available protocol
names: icmp, igmp, ip, tcp, egp, igp, udp, hmp, rdp, idpr, ipv6, ipv6:rout,
ipv6:frag, idrp, rsvp, gre, esp, ah, ipv6:icmp, eigrp, ospf, ipinip, pim, l2tp, isis.
To match any protocol, use the Ip keyword. (Range: 0–255)
•
source
—Source IP address of the packet.
•
source-wildcard
—Wildcard bits to be applied to the source IP address. Use
1s in the bit position that you want to be ignored.
•
destination
—Destination IP address of the packet.
Содержание 300 Series
Страница 2: ......