SUMMARY STEPS
1.
enable
2.
configure terminal
3.
ip access-list extended access-list-name
4.
[
sequence-number
]
permit tcp source source-wildcard
[
operator port
[
port
]]
destination
destination-wildcard
[
operator
[
port
]] [
established
{
match-any
|
match-all
} {
+
|
-
}
flag-name
]
[
precedence precedence
] [
tos tos
] [
log
] [
time-range time-range-name
] [
fragments
]
5.
[
sequence-number
]
deny tcp source source-wildcard
[
operator port
[
port
]]
destination destination-wildcard
[
operator
[
port
]] [
established
{
match-any
|
match-all
} {
+
|
-
}
flag-name
] [
precedence precedence
] [
tos
tos
] [
log
] [
time-range time-range-name
] [
fragments
]
6.
Repeat Step 4 or Step 5 as necessary, adding statements by sequence number where you planned. Use the
no sequence-number
command to delete an entry.
7.
end
8.
show ip access-lists access-list-name
DETAILED STEPS
Purpose
Command or Action
Enables privileged EXEC mode.
enable
Step 1
Example:
Device> enable
•
Enter your password if prompted.
Enters global configuration mode.
configure terminal
Example:
Device# configure terminal
Step 2
Specifies the IP access list by name and enters named access list
configuration mode.
ip access-list extended access-list-name
Example:
Device(config)# ip access-list extended
acl-extd-1
Step 3
Specifies a
permit
statement in named IP access list configuration
mode.
[
sequence-number
]
permit tcp source source-wildcard
[
operator port
[
port
]]
destination destination-wildcard
Step 4
[
operator
[
port
]] [
established
{
match-any
|
•
Operators include
lt
(less than),
gt
(greater than),
eq
(equal),
neq
(not equal), and
range
(inclusive range).
match-all
} {
+
|
-
}
flag-name
] [
precedence
precedence
] [
tos tos
] [
log
] [
time-range
time-range-name
] [
fragments
]
•
If the operator is positioned after the source and
source-wildcard arguments, it must match the source port.
Example:
Device(config-ext-nacl)# permit tcp any eq
telnet ftp any eq 450 679
If the operator is positioned after the destination and
destination-wildcard arguments, it must match the destination
port.
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1192
How to Configure ACLs
Содержание Catalyst 2960 Series
Страница 78: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches lxxviii Contents ...
Страница 96: ......
Страница 184: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 102 Additional References ...
Страница 195: ...P A R T II IP Multicast Routing Configuring IGMP Snooping and Multicast VLAN Registration page 115 ...
Страница 196: ......
Страница 250: ......
Страница 292: ......
Страница 488: ......
Страница 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Страница 590: ......
Страница 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Страница 620: ......
Страница 749: ...P A R T VIII Routing Configuring IP Unicast Routing page 669 Configuring IPv6 First Hop Security page 677 ...
Страница 750: ......
Страница 796: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 714 Additional References ...
Страница 856: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 774 Additional References ...
Страница 1400: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1318 Additional References ...
Страница 1546: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1464 Auto Identity ...
Страница 1596: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1514 Additional References ...
Страница 1604: ......
Страница 1740: ......
Страница 1764: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1682 Additional References ...
Страница 1942: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1860 cli_write ...
Страница 1950: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1868 context_save ...
Страница 2058: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1976 event_register_wdsysmon ...
Страница 2076: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1994 smtp_subst ...
Страница 2090: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2008 sys_reqinfo_syslog_history ...
Страница 2104: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2022 unregister_counter ...
Страница 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Страница 2106: ......
Страница 2118: ......
Страница 2164: ......