78
ACL Commands
Default Configuration
No IPv4 ACL is defined.
Command Mode
IP-Access List Configuration mode.
User Guidelines
•
Use the
ip access-list
Global Configuration mode command to enable the IP-Access List
Configuration mode.
•
Before an Access Control Element (ACE) is added to an ACL, all packets are permitted. After an ACE
is added, an implied
deny-any-any
condition exists at the end of the list and those packets that do not
match the conditions defined in the permit statement are denied.
Example
The following example shows how to define a permit statement for an IP ACL.
deny (IP)
The
deny
IP-Access List Configuration mode command denies
traffic if the conditions defined in the
deny statement match.
Syntax
•
deny
[
disable-port
] {
any
|
protocol
} {
any
|{
source source-wildcard
}} {
any
|{
destination destination-
wildcard
}} [
dscp
number
|
ip-precedence
number
]
•
deny-icmp
[
disable-port
] {
any
|{
source source-wildcard
}} {
any
|{
destination destination-wildcard
}}
{
any
|
icmp-type
} {
any
|
icmp-code
} [
dscp
number
|
ip-precedence
number
]
•
deny-igmp
[
disable-port
] {
any
|{
source source-wildcard
}} {
any
|{
destination destination-wildcard
}}
{
any
|
igmp-type
} [
dscp
number
|
ip-precedence
number
]
•
deny-tcp
[
disable-port
] {
any
|{
source source-wildcard
}} {
any
|
source-port
} {
any
|{
destination
destination-wildcard
}} {
any
|
destination-port
} [
dscp
number
|
ip-precedence number
] [
flags
list-of-
flags
] [
src-port-wildcard
source-port-wildcard
] [
dst-port-wildcard
source-port-wildcard
]
•
deny-udp
[
disable-port
] {
any
|{
source source-wildcard
}} {
any
|
source-port
} {
any
|{
destination
destination-wildcard
}} {
any
|
destination-port
} [
dscp
number
|
ip-precedence
number
] [
src-port-
wildcard
source-port-wildcard
] [
dst-port-wildcard
source-port-wildcard
Console(config)#
ip access-list
ip-acl1
Console(config-ip-al)#
permit
rsvp 192.1.1.1 0.0.0.0
any
dscp
56
5400_CLI.book Page 78 Wednesday, December 17, 2008 4:33 PM
Содержание PowerConnect 5424
Страница 114: ...114 Address Table Commands 5400_CLI book Page 114 Wednesday December 17 2008 4 33 PM ...
Страница 178: ...178 Ethernet Configuration Commands 5400_CLI book Page 178 Wednesday December 17 2008 4 33 PM ...
Страница 194: ...194 GVRP Commands 5400_CLI book Page 194 Wednesday December 17 2008 4 33 PM ...
Страница 204: ...204 IGMP Snooping Commands 5400_CLI book Page 204 Wednesday December 17 2008 4 33 PM ...
Страница 252: ...252 Line Commands 5400_CLI book Page 252 Wednesday December 17 2008 4 33 PM ...
Страница 268: ...268 LLDP Commands 5400_CLI book Page 268 Wednesday December 17 2008 4 33 PM ...
Страница 280: ...280 PHY Diagnostics Commands 5400_CLI book Page 280 Wednesday December 17 2008 4 33 PM ...
Страница 288: ...288 Port Monitor Commands 5400_CLI book Page 288 Wednesday December 17 2008 4 33 PM ...
Страница 300: ...300 QoS Commands 5400_CLI book Page 300 Wednesday December 17 2008 4 33 PM ...
Страница 308: ...308 Radius Commands 5400_CLI book Page 308 Wednesday December 17 2008 4 33 PM ...
Страница 326: ...326 RMON Commands 5400_CLI book Page 326 Wednesday December 17 2008 4 33 PM ...
Страница 386: ...386 SSH Commands 5400_CLI book Page 386 Wednesday December 17 2008 4 33 PM ...
Страница 400: ...400 Syslog Commands 5400_CLI book Page 400 Wednesday December 17 2008 4 33 PM ...
Страница 418: ...418 System Management 5400_CLI book Page 418 Wednesday December 17 2008 4 33 PM ...
Страница 432: ...432 TIC Commands 5400_CLI book Page 432 Wednesday December 17 2008 4 33 PM ...
Страница 440: ...440 Tunnel 5400_CLI book Page 440 Wednesday December 17 2008 4 33 PM ...
Страница 476: ...476 Voice VLAN 5400_CLI book Page 476 Wednesday December 17 2008 4 33 PM ...
Страница 490: ...490 Web Server 5400_CLI book Page 490 Wednesday December 17 2008 4 33 PM ...