Configuring Access Control Lists
613
{
deny
|
permit
} {
every
|
{{
ipv4-protocol
|
0-255
|
every
} {
srcip srcmask
|
any
|
host
srcip
} [{
range
{
portkey
|
startport
}
{
portkey
|
endport
} |
{
eq
|
neq
|
lt
|
gt
}
{
portkey
|
0-65535
} ]
{
dstip dstmask
|
any
|
host
dstip
} [{
range
{
portkey
|
startport
}
{
portkey
|
endport
} |
{
eq
|
neq
|
lt
|
gt
}
{
portkey
|
0-65535
}]
[
flag
[
+fin
|
-fin
] [
+syn
|
-syn
] [
+rst
|
-rst
]
[
+psh
|
-psh
] [
+ack
|
-
ack
] [
+urg
|
-urg
]
[
established
]] [
icmp-
type
icmp-type
[
icmp-
code
icmp-code
] |
icmp-
message
icmp-message
]
[
igmp-type
igmp-type
]
[
fragments
] [
precedence
precedence
|
tos
tos
[
tosmask
] |
dscp
dscp
]}} [
time-range
time-range-name
] [
log
]
[
assign-queue
queue-id
]
[{
mirror
|
redirect
}
unit/slot/port
] [
rate-
limit
rate burst-size
]
Enter the permit and deny conditions for the extended
ACL.
• {
deny | permit
}–Specifies whether the IP ACL rule
permits or denies the matching traffic.
• {
ipv4-protocol
|
number
|
every
}—Specifies the
protocol to match for the IP ACL rule.
– IPv4 protocols:
eigrp, gre, icmp, igmp, ip, ipinip, ospf,
tcp, udp, pim
–
Every
: Match any protocol (don’t care)
•
srcip
srcmask
| any | host
srcip
—Specifies a source IP
address and netmask to match for the IP ACL rule.
– Specifying “any” implies specifying
srcip
as “0.0.0.0”
and
srcmask
as “255.255.255.255” for IPv4.
– Specifying “host A.B.C.D” implies
srcip
as “A.B.C.D”
and
srcmask
as “0.0.0.0”.
• [{{eq | neq | lt | gt} {
portkey
|
number
} | range
startport endport
}]—Specifies the layer 4 destination
port match condition for the IP ACL rule. A destination
port number, which ranges from 0-65535, can be entered,
or a
portkey
, which can be one of the following keywords:
domain, echo, ftp, ftp-data, http, smtp, snmp, telnet,
tftp, and www. Each of these keywords translates into its
equivalent destination port number.
– When “range” is specified, IP ACL rule matches only if
the layer 4 port number falls within the specified
portrange. The
startport
and
endport
parameters
identify the first and last ports that are part of the port
range. They have values from 0 to 65535. The ending
port must have a value equal or greater than the
starting port. The starting port, ending port, and all
ports in between will be part of the layer 4 port range.
Command
Purpose
Содержание N2000 Series
Страница 50: ...50 Contents ...
Страница 54: ...54 Introduction ...
Страница 134: ...134 Using Dell OpenManage Switch Administrator ...
Страница 168: ...168 Setting Basic Network Information ...
Страница 206: ...206 Managing a Switch Stack ...
Страница 242: ...242 Configuring Authentication Authorization and Accounting ...
Страница 318: ...318 Managing General System Settings Figure 12 24 Verify MOTD ...
Страница 322: ...322 Managing General System Settings ...
Страница 344: ...344 Configuring SNMP Figure 13 18 Trap Logs Click Clear to delete all entries from the trap log ...
Страница 358: ...358 Configuring SNMP ...
Страница 388: ...388 Managing Images and Files ...
Страница 415: ...Monitoring Switch Traffic 415 Figure 16 2 sFlow Agent Summary ...
Страница 451: ...Monitoring Switch Traffic 451 5 On the Capture Options dialog click Manage Interfaces ...
Страница 458: ...458 Monitoring Switch Traffic ...
Страница 488: ...488 Configuring Port Characteristics Figure 18 3 Copy Port Settings 8 Click Apply ...
Страница 502: ...502 Configuring Port Characteristics ...
Страница 541: ...Configuring Port and System Security 541 Figure 19 12 Configure Port Security Settings 5 Click Apply ...
Страница 567: ...Configuring Port and System Security 567 Figure 19 38 Captive Portal Client Status ...
Страница 666: ...666 Configuring VLANs Figure 21 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 674: ...674 Configuring VLANs Figure 21 17 GVRP Port Parameters Table ...
Страница 680: ...680 Configuring VLANs Figure 21 24 Double VLAN Port Parameter Table ...
Страница 714: ...714 Configuring VLANs ...
Страница 737: ...Configuring the Spanning Tree Protocol 737 Figure 22 9 Spanning Tree Global Settings ...
Страница 760: ...760 Configuring the Spanning Tree Protocol ...
Страница 786: ...786 Discovering Network Devices ...
Страница 793: ...Configuring Port Based Traffic Control 793 Figure 24 3 Storm Control 5 Click Apply ...
Страница 878: ...878 Configuring Connectivity Fault Management ...
Страница 899: ...Snooping and Inspecting Traffic 899 Figure 27 17 DAI Interface Configuration Summary ...
Страница 903: ...Snooping and Inspecting Traffic 903 Figure 27 24 Dynamic ARP Inspection Statistics ...
Страница 924: ...924 Configuring Link Aggregation Figure 28 7 LAG Hash Summary ...
Страница 982: ...982 Configuring Link Aggregation ...
Страница 1062: ...1062 Configuring DHCP Server and Relay Settings ...
Страница 1096: ...1096 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 1200: ...1200 Configuring OSPF and OSPFv3 ...
Страница 1216: ...1216 Configuring RIP ...
Страница 1240: ...1240 Configuring VRRP ...
Страница 1284: ...1284 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1291: ...Configuring Differentiated Services 1291 Figure 40 5 DiffServ Class Criteria ...
Страница 1336: ...1336 Configuring Auto VoIP ...
Страница 1367: ...Managing IPv4 and IPv6 Multicast 1367 Figure 43 20 IGMP Cache Information ...
Страница 1422: ...1422 Managing IPv4 and IPv6 Multicast ...
Страница 1440: ...1440 System Process Definitions ...
Страница 1460: ...Index 1460 ...