5000 Series Layer 2/3 Managed Data Center Switch CLI Reference Guide
1199
Specifying
icmp-message
implies that both icmp-type and icrnp-code
are specified. The following icmp-messages are supported: echo, echo-
reply, host-redirect, mobile-redirect, net-redirect, net-unreachable,
redirect, packet-too-big, port-unreachable, source-quench, router-
solicitation, router-advertisement, time-exceeded, ttI-exceeded and
unreachable.
igmp-type igmp-type
This option is available only if the protocol is igmp.
When
igmp-type
is specified, the IP ACL rule matches on the specified
IGMP message type, a number from 0 to 255.
fragments
Specifies that the IP ACL rule matches on fragmented IP packets.
Log
Specifies that this rule is to be logged.
time-range time-range-name
Allows imposing time limitation on the ACL rule as defined by the
parameter time-range-name. If a time range with the specified name
does not exist and the ACL containing this ACL rule is applied to an
interface or bound to a VLAN, then the ACL rule is applied immediately.
If a time range with specified name exists and the ACL containing this
ACL rule is applied to an interface or bound to a VLAN, the ACL rule is
applied when the time-range with specified name becomes active. The
ACL rule is removed when the time-range with specified name becomes
inactive. For information about configuring time ranges, see
Range Commands for Time-Based ACLs”
.
assign-queue queue-id
Specifies the assign-queue, which is the queue identifier to which
packets matching this rule are assigned.
{mirror | redirect} slot/port
Specifies the mirror or redirect interface which is the
slot/port
to which
packets matching this rule are copied or forwarded, respectively.
rate-limit rate burst-size
Specifies the allowed rate of traffic as per the configured rate in kbps,
and burst-size in kbytes.
Default
The default is None.
Command Mode
Global Config
12-73 ip access-list
This command creates an extended IP Access Control List (ACL) identified by name, consisting of
classification fields defined for the IP header of an IPv4 frame. The
name
parameter is a case-sensitive
alphanumeric string from 1 to 31 characters uniquely identifying the IP access list.
lf an lP ACL by this name already exists, this command enters IPv4-Access_List config mode to allow
updating the existing IP ACL.
Note:
The CLI mode changes to IPv4-Access-Lis Config mode when you successfully execute this
command.
Use the
no
command to delete the IP ACL identified by name from the system.
ip access-list name
Содержание 5000 Series
Страница 1: ...Draft 1 2 1 ...
Страница 141: ...5000 Series Layer 2 3 Managed Data Center Switch CLI Reference Guide 135 ...