560
Configuring Network Security with ACLs
How to Configure Network Security with ACLs
Applying an IPv4 ACL to a Terminal Line
This task restricts incoming and outgoing connections between a virtual terminal line and the addresses in an ACL:
Applying an IPv4 ACL to an Interface
Command
Purpose
1.
configure terminal
Enters global configuration mode.
2.
time-range
time-range-name
Assigns a meaningful name (for example,
workhours
) to the time range
to be created, and enters time-range configuration mode. The name
cannot contain a space or quotation mark and must begin with a letter.
3.
absolute
[
start
time date
]
[
end
time date
]
or
periodic
day-of-the-week hh:mm to
[
day-of-the-week
]
hh:mm
or
periodic
{
weekdays
|
weekend
|
daily
}
hh:mm to hh:mm
Specifies when the function it will be applied to is operational.
You can use only one
absolute
statement in the time range. If you
configure more than one absolute statement, only the one
configured last is executed.
You can enter multiple
periodic
statements. For example, you could
configure different hours for weekdays and weekends.
See the example configurations.
4.
end
Returns to privileged EXEC mode.
Command
Purpose
1.
configure terminal
Enters global configuration mode.
2.
line
[
console
|
vty
]
line-number
Identifies a specific line to configure, and enters in-line configuration mode.
console
—Specifies the console terminal line. The console port is DCE.
vty
—Specifies a virtual terminal for remote console access.
The
line-number
is the first line number in a contiguous group that you want
to configure when the line type is specified. The range is from 0 to 16.
3.
access-class
access-list-number
{
in
|
out
}
Restricts incoming and outgoing connections between a particular virtual
terminal line (into a device) and the addresses in an access list.
4.
end
Returns to privileged EXEC mode.
Command
Purpose
1.
configure terminal
Enters global configuration mode.
2.
interface
interface-id
Identifies a specific interface for configuration, and enters interface
configuration mode.
The interface is a Layer 2 interface (port ACL).
3.
ip access-group
{
access-list-number
| name
} {
in
|
out
}
Controls access to the specified interface.
The
out
keyword is not supported for Layer 2 interfaces (port ACLs).
4.
end
Returns to privileged EXEC mode.
Содержание IE 4000
Страница 12: ...8 Configuration Overview Default Settings After Initial Switch Configuration ...
Страница 52: ...48 Configuring Interfaces Monitoring and Maintaining the Interfaces ...
Страница 108: ...104 Configuring Switch Clusters Additional References ...
Страница 128: ...124 Performing Switch Administration Additional References ...
Страница 130: ...126 Configuring PTP ...
Страница 140: ...136 Configuring CIP Additional References ...
Страница 146: ...142 Configuring SDM Templates Configuration Examples for Configuring SDM Templates ...
Страница 192: ...188 Configuring Switch Based Authentication Additional References ...
Страница 244: ...240 Configuring IEEE 802 1x Port Based Authentication Additional References ...
Страница 274: ...270 Configuring SGT Exchange Protocol over TCP SXP and Layer 3 Transport Configuring Cisco TrustSec Caching ...
Страница 298: ...294 Configuring VLANs Additional References ...
Страница 336: ...332 Configuring STP Additional References ...
Страница 408: ...404 Configuring DHCP Additional References ...
Страница 450: ...446 Configuring IGMP Snooping and MVR Additional References ...
Страница 490: ...486 Configuring SPAN and RSPAN Additional References ...
Страница 502: ...498 Configuring Layer 2 NAT ...
Страница 559: ...555 Configuring Network Security with ACLs How to Configure Network Security with ACLs Creating a Numbered Extended ACL ...
Страница 770: ...766 Configuring IPv6 MLD Snooping Related Documents ...
Страница 930: ...926 Configuring IP Unicast Routing Related Documents ...
Страница 956: ...952 Configuring IPv6 Unicast Routing Configuring IPv6 network 2010 AB8 2 48 network 2010 AB8 3 48 exit address family ...
Страница 976: ...972 Configuring Cisco IOS IP SLAs Operations Additional References ...
Страница 978: ...974 Dying Gasp ...
Страница 990: ...986 Configuring Enhanced Object Tracking Monitoring Enhanced Object Tracking ...
Страница 994: ...990 Configuring MODBUS TCP Displaying MODBUS TCP Information ...
Страница 996: ...992 Ethernet CFM ...
Страница 1030: ...1026 Working with the Cisco IOS File System Configuration Files and Software Images Working with Software Images ...
Страница 1066: ...1062 Using an SD Card SD Card Alarms ...