Extended IP ACL Commands
When an ACL is created without any rule and then applied to an interface, ACL behavior reflects an
implicit permit.
The following commands configure extended IP ACLs, which in addition to the IP address, also examine
the packet’s protocol type.
The supports both Ingress and Egress IP ACLs.
NOTE: Also refer to the
Commands Common to all ACL Types
sections.
deny
Configure a filter that drops IP packets meeting the filter criteria.
S6000
Syntax
deny {ip |
ip-protocol-number
} {
source mask
| any | host
ip-
address
} {
destination
mask | any | host
ip-address
} [count
[byte] | log] [dscp
value
] [order] [monitor] [fragments]
To remove this filter, you have two choices:
• Use the
no seq
sequence-number
command if you know the filter’s
sequence number.
• Use the
no deny {ip |
ip-protocol-number
} {
source mask
| any |
host
ip-address
} {
destination mask
| any | host
ip-address
}
command.
Parameters
ip
Enter the keyword
ip
to configure a generic IP access list.
The keyword
ip
specifies that the access list denies all IP
protocols.
ip-protocol-
number
Enter a number from 0 to 255 to deny based on the protocol
identified in the IP protocol header.
source
Enter the IP address of the network or host from which the
packets were sent.
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The
mask, when specified in A.B.C.D format, may be either
contiguous or noncontiguous.
any
Enter the keyword
any
to specify that all routes are subject
to the filter.
host
ip-address
Enter the keyword
host
then the IP address to specify a host
IP address.
destination
Enter the IP address of the network or host to which the
packets are sent.
count
(OPTIONAL) Enter the keyword
count
to count packets that
the filter processes.
Access Control Lists (ACL)
185
Содержание Networking S6000 System
Страница 1: ...Dell Command Line Reference Guide for the S6000 System 9 5 0 0 ...
Страница 558: ...Version 8 3 10 0 Introduced on the S4810 558 Equal Cost Multi Path ECMP ...
Страница 579: ...Version 8 3 12 0 Introduced on the S4810 FCoE Transit 579 ...
Страница 773: ...dropped in keepalive Dell Related Commands show ip cam stack unit displays the CAM table IPv4 Routing 773 ...
Страница 1319: ...Gi1 2 2 STP PVST Dell Related Commands show running config displays the current configuration Service Provider Bridging 1319 ...
Страница 1331: ...Gi 3 40 configured rate 16384 actual rate 16384 sub sampling rate 1 Dell sFlow 1331 ...
Страница 1480: ...Version 8 3 8 0 Introduced on the S4810 1480 Virtual Link Trunking VLT ...