Purpose
Command or Action
port
] [
established
] [
precedence precedence
]
[
tos tos
] [
fragments
] [
log
[
log-input
]
(Optional) Enter an
operator
and
port
to compare source (if positioned after
source source-wildcard
) or destination (if positioned after
destination
destination-wildcard
) port. Possible operators include
eq
(equal),
gt
(greater
[
time-range time-range-name
] [
dscp dscp
]
[
flag
]
than),
lt
(less than),
neq
(not equal), and
range
(inclusive range). Operators
require a port number (range requires two port numbers separated by a space).
Example:
Switch(config)#
access-list 101 permit
Enter the
port
number as a decimal number (from 0 to 65535) or the name of
a TCP port. Use only TCP port numbers or names when filtering TCP.
tcp any any eq 500
The other optional keywords have these meanings:
•
established
—
Enter to match an established connection. This has the
same function as matching on the
ack
or
rst
flag.
•
flag
—
Enter one of these flags to match by the specified TCP header
bits:
ack
(acknowledge),
fin
(finish),
psh
(push),
rst
(reset),
syn
(synchronize), or
urg
(urgent).
(Optional) Defines an extended UDP access list and the access conditions.
access-list access-list-number
{
deny
|
permit
}
udp source source-wildcard
Step 4
The UDP parameters are the same as those described for TCP except that the
[operator [port]] port number or name must be a UDP port number or name,
and the
flag
and
established
keywords are not valid for UDP.
[
operator port
]
destination
destination-wildcard
[
operator port
]
[
precedence precedence
] [
tos tos
]
[
fragments
] [
log
[
log-input
] [
time-range
time-range-name
] [
dscp dscp
]
Example:
Switch(config)#
access-list 101 permit
udp any any eq 100
Defines an extended ICMP access list and the access conditions.
access-list access-list-number
{
deny
|
permit
}
icmp source source-wildcard
Step 5
The ICMP parameters are the same as those described for most IP protocols
in an extended IPv4 ACL, with the addition of the ICMP message type and
code parameters. These optional keywords have these meanings:
destination destination-wildcard
[
icmp-type
|
[[
icmp-type icmp-code
] | [
icmp-message
]]
[
precedence precedence
] [
tos tos
]
•
icmp-type
—
Enter to filter by ICMP message type, a number from 0
to 255.
[
fragments
] [
time-range time-range-name
]
[
dscp dscp
]
Example:
Switch(config)#
access-list 101 permit
•
icmp-code
—
Enter to filter ICMP packets that are filtered by the ICMP
message code type, a number from 0 to 255.
•
icmp-message
—
Enter to filter ICMP packets by the ICMP message type
name or the ICMP message type and code name.
icmp any any 200
(Optional) Defines an extended IGMP access list and the access conditions.
access-list access-list-number
{
deny
|
permit
}
igmp source source-wildcard
Step 6
The IGMP parameters are the same as those described for most IP protocols
in an extended IPv4 ACL, with this optional parameter.
destination destination-wildcard
[
igmp-type
]
[
precedence precedence
] [
tos tos
]
igmp-type
—
To match IGMP message type, enter a number from 0 to 15, or
enter the message name:
dvmrp
,
host-query
,
host-report
,
pim
, or
trace
.
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1187
How to Configure ACLs
Содержание Catalyst 2960 Series
Страница 78: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches lxxviii Contents ...
Страница 96: ......
Страница 184: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 102 Additional References ...
Страница 195: ...P A R T II IP Multicast Routing Configuring IGMP Snooping and Multicast VLAN Registration page 115 ...
Страница 196: ......
Страница 250: ......
Страница 292: ......
Страница 488: ......
Страница 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Страница 590: ......
Страница 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Страница 620: ......
Страница 749: ...P A R T VIII Routing Configuring IP Unicast Routing page 669 Configuring IPv6 First Hop Security page 677 ...
Страница 750: ......
Страница 796: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 714 Additional References ...
Страница 856: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 774 Additional References ...
Страница 1400: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1318 Additional References ...
Страница 1546: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1464 Auto Identity ...
Страница 1596: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1514 Additional References ...
Страница 1604: ......
Страница 1740: ......
Страница 1764: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1682 Additional References ...
Страница 1942: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1860 cli_write ...
Страница 1950: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1868 context_save ...
Страница 2058: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1976 event_register_wdsysmon ...
Страница 2076: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1994 smtp_subst ...
Страница 2090: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2008 sys_reqinfo_syslog_history ...
Страница 2104: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2022 unregister_counter ...
Страница 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Страница 2106: ......
Страница 2118: ......
Страница 2164: ......