![Cisco Small Business 300 1.1 Series Скачать руководство пользователя страница 537](http://html.mh-extra.com/html/cisco/small-business-300-1-1-series/small-business-300-1-1-series_administration-manual_2609294537.webp)
ACL Commands
78-20269-01 Command Line Interface Reference Guide
538
40
nameserver (42), netbios-dgm (138), netbios-ns (137), non500-isakmp
(4500), ntp (123), rip (520), snmp 161), snmptrap (162), sunrpc (111), syslog
(514), tacacs-ds (49), talk (517), tftp (69), time (37), who (513), xdmcp (177).
(Range: 0–65535)
•
source-port—Specifies the UDP/TCP source port. Predefined port names
are defined in the destination-port parameter. (Range: 0–65535)
•
match-all
list-of-flags
—List of TCP flags that should occur. If a flag should be
set it is prefixed by “+”.If a flag should be unset it is prefixed by “-”. Available
options are +urg, +ack, +psh, +rst, +syn, +fin, -urg, -ack, -psh, -rst, -syn and
-fin. The flags are concatenated to a one string. For example: +fin-ack.
•
disable-port—The Ethernet interface is disabled if the condition is matched.
•
log-input—Specifies sending an informational syslog message about the
packet that matches the entry. Because forwarding is done in hardware and
logging is done in software, if a large number of packets match a deny ACE
containing a log-input keyword, the software might not be able to match the
hardware processing rate, and not all packets will be logged.
Default Configuration
No IPv4 access list is defined.
Command Mode
IP Access-list Configuration mode
User Guidelines
After an ACE is added to an access control list, an implicit deny any any condition
exists at the end of the list. That is, if there are no matches, the packets are denied.
However, before the first ACE is added, the list permits all packets.
The number of TCP/UDP ranges that can be defined in ACLs is limited. You can
define up to #ASIC-specific ranges for TCP and up to #ASIC-specific ranges for
UDP. If a range of ports is used for a source port in ACE it is not counted again if it is
also used for source port in another ACE. If a range of ports is used for destination
port in ACE it is not counted again if it is also used for destination port in another
ACE.
If a range of ports is used for source port, it is counted again if it is also used for
destination port.
Example
Содержание Small Business 300 1.1 Series
Страница 1: ...Cisco Small Business 300 1 1 Series Managed Switch Administration Guide CLI GUIDE ...
Страница 527: ...DHCP Relay Commands 78 20269 01 Command Line Interface Reference Guide 528 38 Servers 1 1 1 1 2 2 2 2 ...
Страница 705: ...Revision History 78 20269 01 Command Line Interface Reference Guide 936 4 ...