ip-protocol-
number
Enter a number from 0 to 255 to deny based on the protocol identified
in the IP protocol header.
source
Enter the IP address of the network or host from which the packets
were sent.
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask,
when specified in A.B.C.D format, may be either contiguous or
noncontiguous.
any
Enter the keyword
any
to specify that all routes are subject to the
filter.
host
ip-address
Enter the keyword
host
and then enter the IP address to specify a
host IP address.
destination
Enter the IP address of the network or host to which the packets are
sent.
count
(OPTIONAL) Enter the keyword
count
to count packets that the filter
processes.
byte
(OPTIONAL) Enter the keyword
byte
to count bytes that the filter
processes.
log
(OPTIONAL, E-Series only) Enter the keyword
log
to enter ACL
matches in the log.
dscp
(OPTIONAL) Enter the keyword
dcsp
to match to the IP DCSCP
values.
order
(OPTIONAL) Enter the keyword
order
to specify the QoS priority for
the ACL entry. The range is 0 to 254 (where 0 is the highest priority
and 254 is the lowest; lower-order numbers have a higher priority). If
you do not use the keyword
order
, the ACLs have the lowest order
by default (255).
monitor
(OPTIONAL) Enter the keyword
monitor
when the rule is describing
the traffic that you want to monitor and the ACL in which you are
creating the rule is applied to the monitored interface. For more
information, refer to the “Flow-based Monitoring” section in the Port
Monitoring chapter of the
FTOS Configuration Guide
.
fragments
Enter the keyword
fragments
to use ACLs to control packet
fragments.
Defaults
Not configured.
Command Modes
CONFIGURATION-EXTENDED-ACCESS-LIST
Command History
Version 8.3.11.1
Introduced on the Z9000.
Version 8.3.7.0
Introduced on the S4810.
Version 8.3.1.0
Add the DSCP value for ACL matching.
Version 8.2.1.0
Allows ACL control of fragmented packets for IP (Layer 3) ACLs.
Version 8.1.1.0
Introduced on the E-Series ExaScale.
227
Содержание Force10 Z9000
Страница 1: ...FTOS Command Line Reference Guide for the Z9000 System FTOS 9 1 0 0 ...
Страница 96: ...96 ...
Страница 194: ...194 ...
Страница 312: ...312 ...
Страница 540: ...540 ...
Страница 546: ...546 ...
Страница 560: ...560 ...
Страница 566: ...566 ...
Страница 590: ...action act UpdateCounter param0 1 0x01 param1 0 0x00 output truncated 590 ...
Страница 624: ...624 ...
Страница 638: ...638 ...
Страница 648: ...648 ...
Страница 659: ...Related Commands show gvrp displays the GVRP configuration 659 ...
Страница 660: ...660 ...
Страница 834: ...834 ...
Страница 854: ...854 ...
Страница 906: ...906 ...
Страница 914: ...914 ...
Страница 976: ...976 ...
Страница 990: ...990 ...
Страница 1006: ...1006 ...
Страница 1008: ...1008 ...
Страница 1026: ...1026 ...
Страница 1145: ...10 211 1 2 Outgoing interface list GigabitEthernet 8 0 1145 ...
Страница 1146: ...1146 ...
Страница 1156: ...1156 ...
Страница 1166: ...1166 ...
Страница 1180: ...1180 ...
Страница 1258: ...1258 ...
Страница 1272: ...1272 ...
Страница 1394: ...1394 ...
Страница 1400: ...1400 ...
Страница 1410: ...1410 ...
Страница 1423: ...To display the type of STP guard Portfast BPDU root or loop guard enabled on a port enter the show spanning tree 0 command 1423 ...
Страница 1424: ...1424 ...
Страница 1444: ...1444 ...
Страница 1456: ...FTOS config interface vlan 40 FTOS conf if vlan tagged TenGi 8 0 FTOS conf if vlan exit FTOS config 1456 ...
Страница 1468: ...Version 8 3 8 0 Introduced on the S4810 1468 ...
Страница 1470: ...1470 ...