100
Summit24e3 Switch Installation and User Guide
Access Policies
Access Control List Examples
This section presents three access control list examples:
•
Using the permit-establish keyword
•
Filtering ICMP packets
•
Using a rate limit
Using the Permit-Established Keyword
This example uses an access list that permits TCP sessions (Telnet, FTP, and HTTP) to be established in
one direction.
The switch, shown in Figure 12, is configured as follows:
•
Two VLANs, NET10 VLAN and NET20 VLAN, are defined.
•
The NET10 VLAN is connected to port 2 and the NET20 VLAN is connected to port 10
•
The IP addresses for NET10 VLAN is 10.10.10.1/24.
•
The IP address for NET20 VLAN is 10.10.20.1/24.
•
The workstations are configured using addresses 10.10.10.100 and 10.10.20.100.
•
IPForwarding is enabled.
Figure 12: Permit-established access list example topology
The following sections describe the steps used to configure the example.
Step 1 – Deny IP Traffic.
delete access-mask <name>
Deletes an access mask. Any access lists or rate
limits that reference this mask must first be
deleted.
delete rate-limit <name>
Deletes a rate limit.
show access-list {<name> | ports <portlist>}
Displays access-list information.
show access-mask {<name>}
Displays access-list information.
show rate-limit {<name> | ports <portlist>}
Displays access-list information.
Table 25: Access Control List Configuration Commands (continued)
Command
Description
EW_087
10.10.10.1
10.10.10.100
10.10.20.100
10.10.20.1
NET20 VLAN
NET10 VLAN
Содержание Summit Summit24
Страница 12: ...12 Contents Summit24e3 Switch Installation and User Guide Index Index of Commands ...
Страница 14: ...14 Figures Summit24e3 Switch Installation and User Guide ...
Страница 24: ...24 Summit24e3 Switch Installation and User Guide Summit24e3 Switch Overview ...
Страница 32: ...32 Summit24e3 Switch Installation and User Guide Switch Installation ...
Страница 78: ...78 Summit24e3 Switch Installation and User Guide Configuring Ports on a Switch ...
Страница 118: ...118 Summit24e3 Switch Installation and User Guide Network Address Translation NAT ...
Страница 132: ...132 Summit24e3 Switch Installation and User Guide Ethernet Automatic Protection Switching ...
Страница 146: ...146 Summit24e3 Switch Installation and User Guide Quality of Service QoS ...
Страница 158: ...158 Summit24e3 Switch Installation and User Guide Status Monitoring and Statistics ...
Страница 204: ...204 Summit24e3 Switch Installation and User Guide Interior Gateway Routing Protocols ...
Страница 212: ...212 Summit24e3 Switch Installation and User Guide Safety Information ...
Страница 216: ...216 Summit24e3 Switch Installation and User Guide Supported Standards ...
Страница 238: ...238 Index Summit24e3 Switch Installation and User Guide ...
Страница 244: ...244 Index of Commands Summit24e3 Switch Installation and User Guide ...