Configure an Extended IP ACL
Extended IP ACLs filter on source and destination IP addresses, IP host addresses, TCP addresses, TCP
host addresses, UDP addresses, and UDP host addresses.
The traffic passes through the filter in the order of the filter’s sequence and hence you can configure the
extended IP ACL by first entering IP ACCESS LIST mode, and then assigning a sequence number to the
filter.
Configuring Filters with a Sequence Number
To configure filters with a sequence number, use the following commands.
1.
Enter IP ACCESS LIST mode by creating an extended IP ACL.
CONFIGURATION mode
ip access-list extended
access-list-name
2.
Configure a drop or forward filter.
CONFIG-EXT-NACL mode
seq
sequence-number
{deny | permit} {
ip-protocol-number
| icmp | ip | tcp |
udp} {
source mask
| any | host
ip-address
} {
destination mask
| any | host
ip-address
} [
operator port
[
port
]] [count [byte]] [order] [fragments]
When you use the
log
keyword, the CP logs details about the packets that match. Depending on how
many packets match the log entry and at what rate, the CP may become busy as it has to log these
packets’ details.
Configure Filters, TCP Packets
To create a filter for TCP packets with a specified sequence number, use the following commands.
1.
Create an extended IP ACL and assign it a unique name.
CONFIGURATION mode
ip access-list extended
access-list-name
2.
Configure an extended IP ACL filter for TCP packets.
CONFIG-EXT-NACL mode
seq
sequence-number
{deny | permit} tcp {source mask | any | host
ip-
address
} [count [byte]] [order] [fragments]
Configure Filters, UDP Packets
To create a filter for UDP packets with a specified sequence number, use the following commands.
1.
Create an extended IP ACL and assign it a unique name.
CONFIGURATION mode
ip access-list extended
access-list-name
2.
Configure an extended IP ACL filter for UDP packets.
110
Access Control Lists (ACLs)
Содержание S6000-ON
Страница 1: ...Dell Configuration Guide for the S6000 ON System 9 9 0 0 ...
Страница 505: ...Figure 60 Inspecting Configuration of LAG 10 on ALPHA Link Aggregation Control Protocol LACP 505 ...
Страница 508: ...Figure 62 Inspecting a LAG Port on BRAVO Using the show interface Command 508 Link Aggregation Control Protocol LACP ...
Страница 509: ...Figure 63 Inspecting LAG 10 Using the show interfaces port channel Command Link Aggregation Control Protocol LACP 509 ...
Страница 552: ...mac address table static multicast mac address vlan vlan id output range interface 552 Microsoft Network Load Balancing ...
Страница 557: ...Figure 80 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 557 ...
Страница 558: ...Figure 81 Configuring PIM in Multiple Routing Domains 558 Multicast Source Discovery Protocol MSDP ...
Страница 562: ...Figure 83 MSDP Default Peer Scenario 1 562 Multicast Source Discovery Protocol MSDP ...
Страница 563: ...Figure 84 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 563 ...
Страница 564: ...Figure 85 MSDP Default Peer Scenario 3 564 Multicast Source Discovery Protocol MSDP ...
Страница 665: ...Policy based Routing PBR 665 ...
Страница 672: ...ip pim bsr border Remove candidate RP advertisements clear ip pim rp mapping 672 PIM Sparse Mode PIM SM ...
Страница 818: ...Figure 110 Single and Double Tag TPID Match 818 Service Provider Bridging ...
Страница 819: ...Figure 111 Single and Double Tag First byte TPID Match Service Provider Bridging 819 ...
Страница 995: ...Figure 140 Setup OSPF and Static Routes Virtual Routing and Forwarding VRF 995 ...