data:image/s3,"s3://crabby-images/fb3bc/fb3bc0accef7fd7af49aeff496d7414edb75db2e" alt="Extreme Networks ExtremeWare 7.0.0 Скачать руководство пользователя страница 616"
616
ExtremeWare Software 7.0.0 Command Reference Guide
Security Commands
create access-list ip destination source ports
create access-list <name> ip destination [<dest_ipaddress>/<mask> | any]
source [<src_ipaddress>/<src_mask> | any] [permit {<qosprofile>} | deny]
ports [<portlist> | any] {precedence <prec_number>}
Description
Creates a named IP access list that applies to all IP traffic.
Syntax Description
Default
N/A.
Usage Guidelines
The access list is applied to all ingress packets.
Example
The following example defines an access list entry allow102 with precedence 40 that permits all traffic on
any ingress ports to the
10.2.x.x subnet
, and assigns QoS profile Qp3 to those packets:
create access-list allow102 ip dest 10.2.0.0/16 source 0.0.0.0/0 permit qosprofile qp3
ports any precedence 40
The following command defines a default entry that is used to specify an explicit deny:
create access-list denyall ip dest 0.0.0.0/0 source 0.0.0.0/0 deny ports any
History
This command was first available in ExtremeWare 6.0.
name
Specifies the access list name. The access list name can be between 1 and
31 characters.
dest_ipaddress/mask
Specifies an IP destination address and subnet mask. A mask length of 32
indicates a host entry.
any
specifies that any address will match.
src_ipaddress/src_mask
Specifies a source IP address and subnet mask.
any
specifies that any address will match.
permit
Specifies that packets that match the access list description are permitted to
be forward by this switch.
qosprofile
Specifies an optional QoS profile can be assigned to the access list, so that
the switch can prioritize packets accordingly.
deny
Specifies that packets that match the access list description are filtered
(dropped) by the switch.
portlist
Specifies the ingress port(s) on which this rule is applied.
any
specifies that the rule will be applied to all ports.
prec_number
Specifies the access list precedence number. The range is 1 to 25,600.
Содержание ExtremeWare 7.0.0
Страница 88: ...88 ExtremeWare Software 7 0 0 Command Reference Guide Commands for Accessing the Switch ...
Страница 226: ...226 ExtremeWare Software 7 0 0 Command Reference Guide Commands for Configuring Slots and Ports on a Switch ...
Страница 276: ...276 ExtremeWare Software 7 0 0 Command Reference Guide FDB Commands ...
Страница 324: ...324 ExtremeWare Software 7 0 0 Command Reference Guide QoS Commands ...
Страница 342: ...342 ExtremeWare Software 7 0 0 Command Reference Guide NAT Commands ...
Страница 502: ...502 ExtremeWare Software 7 0 0 Command Reference Guide SLB Commands ...
Страница 568: ...568 ExtremeWare Software 7 0 0 Command Reference Guide Commands for Status Monitoring and Statistics ...
Страница 680: ...680 ExtremeWare Software 7 0 0 Command Reference Guide Security Commands ...
Страница 734: ...734 ExtremeWare Software 7 0 0 Command Reference Guide STP Commands ...
Страница 772: ...772 ExtremeWare Software 7 0 0 Command Reference Guide ESRP Commands ...
Страница 1226: ...1226 ExtremeWare Software 7 0 0 Command Reference Guide IPX Commands ...
Страница 1242: ...1242 ExtremeWare Software 7 0 0 Command Reference Guide ARM Commands ...
Страница 1320: ...1320 ExtremeWare Software 7 0 0 Command Reference Guide PoS Commands ...
Страница 1430: ...1430 ExtremeWare Software 7 0 0 Command Reference Guide MPLS Commands ...