958
ExtremeWare 7.7 Command Reference Guide
Security Commands
create access-list
create access-list <name> access-mask <access-mask name> {code-point
<code_point>} {dest-mac <dest_mac} {source-mac <src_mac>} {vlan <name>}
{ethertype [IP | ARP | <hex_value>]} {tos <ip_precedence> | {ip-protocol
[tcp | udp | icmp | igmp | <prococol_num>]} {igmp-type [membership-query |
leave-group | v1-membership-report | v2-membership-report | <number> |
any]} {ipmc-group <multicast IP address>/<mask length>} {dest-ip
<dest_IP>/<masklength>} {dest-L4port <dest_port>} {source-ip <src_IP>/<mask
length>} {source-L4port <src_port> [permit {qosprofile <qosprofile>} {set
code-point <code_point>} {set dot1p <dot1p_value} | permit-established
|deny]{vlan-pri}{vlan-pri-2bits}
Description
Creates an access list on an “e” series switch.
NOTE
This command is available only on the “e” series switches. To create access lists for “i” series switches,
use the following five commands:
create access-list icmp destination source
create access-list ip destination source ports
create access-list tcp destination source ports
create access-list udp destination source ports
create access-list igmp destination source igmp-type ipmc-group ports
Syntax Description
name
Specifies the name of the access list.
access-mask
Specifies the name of the associated access mask.
code-point
Specifies a 6-bit DiffServ code point. Valid entries are from 0 to 63.
dest-mac
Specifies the destination MAC address.
source-mac
Specifies the source MAC address.
vlan
Specifies the VLANid.
ethertype
Specifies the Ethernet type field, either IP or ARP.
tos
Specifies a 3-bit precedence field within the IP ToS field. Valid entries are from 0 to 7.
ip-protocol
Specifies the IP protocol by name (UDP, ICMP, OR IGMP) or by protocol-number.
igmp-type
Specifies the IGMP type. The IGMP type can be membership-query, leave-group, or
v1-membership-report length; or a number between 0 and 255.
ipmc-group/<mask length> Specifies the IP multicast group and the mask.
dest-ip
Specifies the destination IP address.
dest-L4port
Specifies the destination TCP/UDP port.
source-ip
Specifies the source IP address.
source-L4port
Specifies the source TCP/UDP port.
set code-point
Specifies a 6-bit DiffServ code point. Valid entries are from 0 to 63.
set dot1p
Specifies the priorities for 802.1p.
permit-established
Specifies to deny any new TCP session initiation.
Содержание ExtremeWare 7.7
Страница 60: ...60 ExtremeWare 7 7 Command Reference Guide Contents ...
Страница 72: ...72 ExtremeWare 7 7 Command Reference Guide Command Reference Overview ...
Страница 404: ...404 ExtremeWare 7 7 Command Reference Guide VLAN Commands ...
Страница 472: ...472 ExtremeWare 7 7 Command Reference Guide QoS Commands ...
Страница 491: ...show nat ExtremeWare 7 7 Command Reference Guide 491 Platform Availability This command is available on all platforms ...
Страница 492: ...492 ExtremeWare 7 7 Command Reference Guide NAT Commands ...
Страница 890: ...890 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1043: ...enable ssh2 ExtremeWare 7 7 Command Reference Guide 1043 Platform Availability This command is available on all platforms ...
Страница 1066: ...1066 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1076: ...1076 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1130: ...1130 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1164: ...1164 ExtremeWare 7 7 Command Reference Guide Configuration and Image Commands ...
Страница 1436: ...1436 ExtremeWare 7 7 Command Reference Guide Wireless Commands ...
Страница 1481: ...show eaps ExtremeWare 7 7 Command Reference Guide 1481 Platform Availability This command is available on all platforms ...
Страница 1484: ...1484 ExtremeWare 7 7 Command Reference Guide EAPS Commands Platform Availability This command is available on all platforms ...
Страница 1490: ...1490 ExtremeWare 7 7 Command Reference Guide EAPS Commands ...
Страница 1538: ...1538 ExtremeWare 7 7 Command Reference Guide ESRP Commands Platform Availability This command is available on all platforms ...
Страница 1576: ...1576 ExtremeWare 7 7 Command Reference Guide ESRP Commands ...
Страница 1614: ...1614 ExtremeWare 7 7 Command Reference Guide STP Commands Platform Availability This command is available on all platforms ...
Страница 1621: ...enable stpd ports ExtremeWare 7 7 Command Reference Guide 1621 Platform Availability This command is available on all platforms ...
Страница 1774: ...1774 ExtremeWare 7 7 Command Reference Guide IP Unicast Commands ...
Страница 1824: ...1824 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1884: ...1884 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1914: ...1914 ExtremeWare 7 7 Command Reference Guide IGP Commands ...
Страница 2000: ...2000 ExtremeWare 7 7 Command Reference Guide BGP Commands i Series Switches Only ...
Страница 2140: ...2140 ExtremeWare 7 7 Command Reference Guide IPX Commands i Series Platforms Only ...
Страница 2156: ...2156 ExtremeWare 7 7 Command Reference Guide ARM Commands BlackDiamond Switch Only ...
Страница 2168: ...2168 ExtremeWare 7 7 Command Reference Guide Remote Connect Commands ...
Страница 2180: ...2180 ExtremeWare 7 7 Command Reference Guide ATM Commands BlackDiamond 6800 Series Platforms Only ...
Страница 2236: ...2236 ExtremeWare 7 7 Command Reference Guide T1 E1 and T3 WAN Commands Alpine 3800 Series Platforms ...
Страница 2346: ...2346 ExtremeWare 7 7 Command Reference Guide PoS Commands BlackDiamond Switch Only ...
Страница 2410: ...2410 ExtremeWare 7 7 Command Reference Guide Power Over Ethernet Commands Summit 300 and 400 24p Switches and Alpine PoE Module ...
Страница 2446: ...2446 ExtremeWare 7 7 Command Reference Guide LLDP Commands ...
Страница 2496: ...2496 ExtremeWare 7 7 Command Reference Guide H VPLS Commands BlackDiamond Switch Only ...
Страница 2620: ...2620 ExtremeWare 7 7 Command Reference Guide Index of Commands ...