Rule-Based IP Access Control Lists (ACLs)
December 2005
© Foundry Networks, Inc.
12 - 13
Here is another example of an extended ACL.
The first entry in this ACL denies TCP traffic from the 209.157.21.
x
network to the 209.157.22.x network.
The second entry denies all FTP traffic from the 209.157.21.
x
network to the 209.157.22.x network.
The third entry denies TCP traffic from the 209.157.21.
x
network to the 209.157.22.
x
network, if the TCP port
number of the traffic is less than the well-known TCP port number for Telnet (23), and if the TCP port is not equal
to 5. Thus, TCP packets whose TCP port numbers are 5 or are greater than 23 are allowed.
The fourth entry denies UDP packets from any source to the 209.157.22.
x
network, if the UDP port number from
the source network is 5 or 6 and the destination UDP port is 7 or 8.
The fifth entry permits all packets that are not explicitly denied by the other entries. Without this entry, the ACL
would deny all incoming or outgoing IP traffic on the ports to which you assign the ACL.
The following commands apply ACL 103 to the incoming traffic on ports 2/1 and 2/2.
Configuring Extended Named ACLs
The commands for configuring named ACL entries are different from the commands for configuring numbered
ACL entries. The command to configure a numbered ACL is
access-list
. The command for configuring a named
ACL is
ip access-list
. In addition, when you configure a numbered ACL entry, you specify all the command
parameters on the same command. When you configure a named ACL, you specify the ACL type (standard or
extended) and the ACL number with one command, which places you in the configuration level for that ACL. Once
you enter the configuration level for the ACL, the command syntax is the same as the syntax for numbered ACLs.
Extended ACLs let you permit or deny packets based on the following information:
•
IP protocol
•
Source IP address or host name
•
Destination IP address or host name
•
Source TCP or UDP port (if the IP protocol is TCP or UDP)
•
Destination TCP or UDP port (if the IP protocol is TCP or UDP)
The IP protocol can be one of the following well-known names or any IP protocol number from 0 – 255:
•
Internet Control Message Protocol (ICMP)
•
Internet Group Management Protocol (IGMP)
FastIron SuperX Router(config)# access-list 103 deny tcp 209.157.21.0/24
209.157.22.0/24
FastIron SuperX Router(config)# access-list 103 deny tcp 209.157.21.0/24 eq ftp
209.157.22.0/24
FastIron SuperX Router(config)# access-list 103 deny tcp 209.157.21.0/24
209.157.22.0/24 lt telnet neq 5
FastIron SuperX Router(config)# access-list 103 deny udp any range 5 6
209.157.22.0/24 range 7 8
FastIron SuperX Router(config)# access-list 103 permit ip any any
FastIron SuperX Router(config)# int eth 2/1
FastIron SuperX Router(config-if-2/1)# ip access-group 103 in
FastIron SuperX Router(config-if-2/1)# exit
FastIron SuperX Router(config)# int eth 2/2
FastIron SuperX Router(config-if-2/2)# ip access-group 103 in
FastIron SuperX Router(config)# write memory
Содержание FastIron Edge Switch X424
Страница 36: ...Foundry Configuration Guide for the FESX FSX and FWSX 2 12 Foundry Networks Inc December 2005...
Страница 56: ...Foundry Configuration Guide for the FESX FSX and FWSX 3 20 Foundry Networks Inc December 2005...
Страница 70: ...Foundry Configuration Guide for the FESX FSX and FWSX 4 14 Foundry Networks Inc December 2005...
Страница 198: ...Foundry Configuration Guide for the FESX FSX and FWSX 8 38 Foundry Networks Inc December 2005...
Страница 316: ...Foundry Configuration Guide for the FESX FSX and FWSX 12 26 Foundry Networks Inc December 2005...
Страница 334: ...Foundry Configuration Guide for the FESX FSX and FWSX 13 18 Foundry Networks Inc December 22 2005...
Страница 350: ...Foundry Configuration Guide for the FESX FSX and FWSX 15 12 Foundry Networks Inc December 2005...
Страница 458: ...Foundry Configuration Guide for the FESX FSX and FWSX 18 18 Foundry Networks Inc December 2005...
Страница 712: ...Foundry Configuration Guide for the FESX FSX and FWSX 22 32 Foundry Networks Inc December 2005...
Страница 760: ...Foundry Configuration Guide for the FESX FSX and FWSX A 34 Foundry Networks Inc December 2005...
Страница 796: ...Foundry Configuration Guide for the FESX FSX and FWSX C 18 Foundry Networks Inc December 2005...
Страница 820: ...Foundry Configuration Guide for the FESX FSX and FWSX E 10 Foundry Networks Inc December 2005...