Chapter 5 Configuring Access Lists and Filtering GSS Traffic
Filtering GSS Traffic Using Access Lists
5-4
Cisco Global Site Selector Administration Guide
OL-10410-01
*Any legal port number
Creating an Access List
You can use the
access-list
command in global configuration mode to create an
access list. You must have access to the CLI of each GSS device to create access
lists for that device.
The syntax for the
access-list
command is as follows:
access-list
name
{
permit
|
deny
}
protocol
[
source-address
source-netmask |
host
source-address |
any
]
operator port
[
port
]
[
destination-port
operator port
[
port
]]
The keywords and arguments are as follows:
•
name
—Alphanumeric name used to identify the access list you are creating.
•
permit
—Allows a connection when a packet matches the condition. All
provisions of the condition must be met to make a match.
•
deny
—Prevents a connection when a packet matches the condition. All
provisions of the condition must be met to make a match.
3340
*
TCP
Sticky and Config Agent
communication
3341
*
TCP
Sticky communication source
3342
*
TCP
Sticky and DNS processes
communication
*
5001
TCP
Global sticky mesh protocol traffic
5001
*
TCP
Return traffic of global sticky mesh
protocol traffic
5002
*
UDP
Return traffic of KAL-AP
keepalives
Table 5-1
GSS-Related Ports and Protocols for Inbound Traffic (continued)
Source Port
(Remote
Device)
Destination
Port
(GSS) Protocol
Details