Purpose
Command or Action
•
The
range
operator requires two port numbers. You can
configure up to 10 ports after the
eq
and
neq
operators. All
other operators require one port number.
•
To filter UDP ports, use the UDP syntax of this command.
(Optional) Specifies a
deny
statement in named access list
configuration mode.
[
sequence-number
]
deny tcp source source-wildcard
[
operator port
[
port
]]
destination destination-wildcard
Step 5
[
operator
[
port
]] [
established
{
match-any
|
•
Operators include
lt
(less than),
gt
(greater than),
eq
(equal),
neq
(not equal), and
range
(inclusive range).
match-all
} {
+
|
-
}
flag-name
] [
precedence
precedence
] [
tos tos
] [
log
] [
time-range
time-range-name
] [
fragments
]
•
If the
operator
is positioned after the
source
and
source-wildcard
arguments, it must match the source port.
Example:
Device(config-ext-nacl)# deny tcp any neq 45
565 632
If the
operator
is positioned after the
destination
and
destination-wildcard
arguments, it must match the destination
port.
•
The
range
operator requires two port numbers. You can
configure up to 10 ports after the
eq
and
neq
operators. All
other operators require one port number.
•
To filter UDP ports, use the UDP syntax of this command.
Allows you to revise the access list.
Repeat Step 4 or Step 5 as necessary, adding
statements by sequence number where you planned.
Step 6
Use the
no sequence-number
command to delete an
entry.
(Optional) Exits named access list configuration mode and returns
to privileged EXEC mode.
end
Example:
Device(config-ext-nacl)# end
Step 7
(Optional) Displays the contents of the access list.
show ip access-lists access-list-name
Example:
Device# show ip access-lists kmd1
Step 8
Consolidating Access List Entries with Noncontiguous Ports into One Access List Entry
Perform this task to consolidate a group of access list entries with noncontiguous ports into one access list
entry.
Although this task uses TCP ports, you could use the UDP syntax of the
permit
and
deny
commands to filter
noncontiguous UDP ports.
Although this task uses a
permit
command first, use the
permit
and
deny
commands in the order that achieves
your filtering goals.
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1193
How to Configure ACLs
Содержание Catalyst 2960 Series
Страница 78: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches lxxviii Contents ...
Страница 96: ......
Страница 184: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 102 Additional References ...
Страница 195: ...P A R T II IP Multicast Routing Configuring IGMP Snooping and Multicast VLAN Registration page 115 ...
Страница 196: ......
Страница 250: ......
Страница 292: ......
Страница 488: ......
Страница 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Страница 590: ......
Страница 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Страница 620: ......
Страница 749: ...P A R T VIII Routing Configuring IP Unicast Routing page 669 Configuring IPv6 First Hop Security page 677 ...
Страница 750: ......
Страница 796: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 714 Additional References ...
Страница 856: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 774 Additional References ...
Страница 1400: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1318 Additional References ...
Страница 1546: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1464 Auto Identity ...
Страница 1596: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1514 Additional References ...
Страница 1604: ......
Страница 1740: ......
Страница 1764: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1682 Additional References ...
Страница 1942: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1860 cli_write ...
Страница 1950: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1868 context_save ...
Страница 2058: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1976 event_register_wdsysmon ...
Страница 2076: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1994 smtp_subst ...
Страница 2090: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2008 sys_reqinfo_syslog_history ...
Страница 2104: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2022 unregister_counter ...
Страница 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Страница 2106: ......
Страница 2118: ......
Страница 2164: ......