ACL Commands
Page 40
•
in-port
port-num
— (Optional) Specifies the input port of the devise. In case of egress classification this port
will be devise input port.
•
out-port
port-num
— (Optional) Specifies the output port of the devise.
•
dscp
— Indicates matching the dscp number with the packet dscp value.
•
ip-precedence
— Indicates matching ip-precedence with the packet ip-precedence value.
Default Configuration
This command has no default configuration
Command Mode
IP-Access List Configuration mode
User Guidelines
Use the
ip access-list
Global Configuration mode command to enable the IP-Access List Configuration mode.
Before an Access Control Element (ACE) is added to an ACL, all packets are permitted. After an ACE is added, an
implied
deny-any-any
condition exists at the end of the list and those packets that do not match the defined
conditions are denied.
Example
The following example shows how to define a permit statement for an IP ACL.
Reservation Protocol
rsvp
46
General Routing Encapsulation
gre
47
Encapsulating Security Payload (50)
esp
50
Authentication Header
ah
51
ICMP for IPv6
ipv6-icmp
58
EIGRP routing protocol
eigrp
88
Open Shortest Path Protocol
ospf
89
IP-within-IP Encapsulation Protocol
ipip
94
Protocol Independent Multicast
pim
103
Layer Two Tunneling Protocol
l2tp
115
ISIS over IPv4
isis
124
(any IP protocol)
any
(25504)
Console(config)#
ip access-list
ip-acl1
Console(config-ip-al)#
deny
rsvp 192.1.1.1 0.0.0.255
any
I P P r o t o c o l
A b b r e v i a t e d N a m e
P r o t o c o l N u m b e r
Содержание xStack DWS-3200 Series
Страница 2: ......
Страница 3: ......
Страница 17: ...Table of Contents Page 14 Appendix A Troubleshooting 571 Problem Management 572 Troubleshooting Solutions 572 ...
Страница 25: ...Using the CLI Editing Features Page 22 ...
Страница 91: ...Clock Commands show sntp status Page 88 ...
Страница 101: ...Configuration and Image File Commands show bootvar Page 98 ...
Страница 137: ...GVRP Commands show gvrp error statistics Page 134 ...
Страница 147: ...IGMP Snooping Commands show ip igmp snooping groups Page 144 ...
Страница 163: ...IP Address Commands show hosts Page 160 ...
Страница 177: ...LACP Commands show lacp port channel Page 174 ...
Страница 187: ...Line Commands show line Page 184 ...
Страница 195: ...Management ACL Commands show management access class Page 192 ...
Страница 201: ...PHY Cable Diagnostics Commands show fiber ports optical transceiver Page 198 ...
Страница 217: ...Port Monitor Commands Page 214 ...
Страница 341: ...Spanning Tree Commands show spanning tree Page 338 ...
Страница 395: ...System Management Commands show system mode Page 392 ...
Страница 413: ...User Interface Commands show privilege Page 410 ...
Страница 437: ...VLAN Commands show vlan protocols groups Page 434 ...
Страница 451: ...Web Server Commands show ip https Page 448 ...
Страница 477: ...802 1x Commands show dot1x advanced Page 474 ...
Страница 483: ...Wireless AP BSS Commands data rates Page 480 ...
Страница 517: ...WLAN Domain Commands wlan domain member approve Page 514 ...
Страница 547: ...Wireless AP Radio Commands beacon period Page 544 ...
Страница 555: ...Wireless Rogue AP Commands show wlan rogue aps neighborhood Page 552 ...
Страница 573: ...Wireless WLAN Commands show wlan stations counters Page 570 ...
Страница 581: ...Page 578 ...