852
ExtremeWare Software 7.3.0 Command Reference Guide
Security Commands
create access-list tcp destination source ports
create access-list <name> tcp destination [<dest_ipaddress>/<mask> | any]
ip-port [<dst_port> | range <dst_port_min> <dst_port_max> | any]
source [<src_ipaddress>/<src_mask> | any] ip-port [<src_port> | range
<src_port_min> <src_port_max> | any] [permit <qosprofile> |
permit-established | deny] ports [<portlist> | any] {precedence
<precedence_num>}
Description
Creates a named IP access list that applies to TCP traffic.
Syntax Description
Default
N/A.
name
Specifies the access list name. The access list name can be between 1 and
31 characters.
dest_ipaddress/mask
Specifies an IP destination address and subnet mask. A mask length of 32
indicates a host entry.
any
specifies that any address will match.
dst_port
Specifies a TCP layer 4 port.
any
specifies that all TCP ports will match.
dst_port_min
Specifies the beginning of a TCP layer 4 port range.
dst_port_max
Specifies the end of a TCP layer 4 port range.
src_ipaddress/src_mask
Specifies a source IP address and subnet mask.
any
specifies that any address will match.
src_port
Specifies a TCP layer 4 port.
any
specifies that all TCP ports will match.
src_port_min
Specifies the beginning of a TCP layer 4 port range.
src_port_max
Specifies the end of a TCP layer 4 port range.
permit
Specifies that packets that match the access list description are permitted to
be forward by this switch.
qosprofile
Specifies an optional QoS profile can be assigned to the access list, so that
the switch can prioritize packets accordingly.
permit-established
Specifies that a currently-established TCP session is allowed, but TCP
packets from source to destination (uni-directional) with SYN=1 and ACK=0 (to
initiate a new session) will be dropped.
deny
Specifies that packets that match the access list description are filtered
(dropped) by the switch.
portlist
Specifies the ingress port(s) on which this rule is applied.
any specifies that the rule will be applied to all ports.
prec_number
Specifies the access list precedence number. The range is 1 to 25,600.
Содержание ExtremeWare 7.3.0
Страница 54: ...54 ExtremeWare Software 7 3 0 Command Reference Guide Contents...
Страница 104: ...104 ExtremeWare Software 7 3 0 Command Reference Guide Commands for Accessing the Switch...
Страница 378: ...378 ExtremeWare Software 7 3 0 Command Reference Guide FDB Commands...
Страница 418: ...418 ExtremeWare Software 7 3 0 Command Reference Guide QoS Commands...
Страница 436: ...436 ExtremeWare Software 7 3 0 Command Reference Guide NAT Commands...
Страница 600: ...600 ExtremeWare Software 7 3 0 Command Reference Guide SLB Commands...
Страница 968: ...968 ExtremeWare Software 7 3 0 Command Reference Guide Security Commands...
Страница 1002: ...1002 ExtremeWare Software 7 3 0 Command Reference Guide EAPS Commands...
Страница 1126: ...1126 ExtremeWare Software 7 3 0 Command Reference Guide ESRP Commands...
Страница 1392: ...1392 ExtremeWare Software 7 3 0 Command Reference Guide IGP Commands...
Страница 1478: ...1478 ExtremeWare Software 7 3 0 Command Reference Guide BGP Commands...
Страница 1556: ...1556 ExtremeWare Software 7 3 0 Command Reference Guide IP Multicast Commands...
Страница 1600: ...1600 ExtremeWare Software 7 3 0 Command Reference Guide IPX Commands...
Страница 1616: ...1616 ExtremeWare Software 7 3 0 Command Reference Guide ARM Commands...
Страница 1694: ...1694 ExtremeWare Software 7 3 0 Command Reference Guide PoS Commands...
Страница 1750: ...1750 ExtremeWare Software 7 3 0 Command Reference Guide T1 E1 and T3 WAN Commands...
Страница 1856: ...1856 ExtremeWare Software 7 3 0 Command Reference Guide MPLS Commands...
Страница 1898: ...1898 ExtremeWare Software 7 3 0 Command Reference Guide High Density Gigabit Ethernet Commands...
Страница 1938: ...1938 ExtremeWare Software 7 3 0 Command Reference Guide Power Over Ethernet Commands...
Страница 1988: ...1988 ExtremeWare Software 7 3 0 Command Reference Guide H VPLS Commands...
Страница 2106: ...2106 ExtremeWare Software 7 3 0 Command Reference Guide Wireless Commands...
Страница 2132: ...2132 ExtremeWare Software 7 3 0 Command Reference Guide Configuration and Image Commands...
Страница 2236: ...2236 ExtremeWare Software 7 3 0 Command Reference Guide Troubleshooting Commands...
Страница 2254: ...2254 ExtremeWare Software 7 3 0 Command Reference Guide Index of Commands...