2094
C
HAPTER
138: IP
V
4 ACL C
ONFIGURATION
C
OMMANDS
rule (in advanced IPv4 ACL view)
Syntax
rule
[
rule-id
] {
deny
|
permit
}
protocol
[
destination
{
dest-addr dest-wildcard
|
any
} |
destination-port
operator port1
[
port2
] |
dscp
dscp |
established
|
fragment
|
icmp-type
{
icmp-type icmp-code
|
icmp-message
} |
logging
|
precedence
precedence
|
reflective
|
source
{
sour-addr sour-wildcard
|
any
} |
source-port
operator port1
[
port2
] |
time-range
time-name
|
tos
tos
|
vpn-instance
vpn-instance-name
] *
undo rule
rule-id
[
destination
|
destination-port
|
dscp
|
established
|
fragment
|
icmp-type
|
logging
|
precedence
|
reflective
|
source
|
source-port
|
time-range
|
tos
|
vpn-instance
] *
View
Advanced IPv4 ACL view
Parameter
rule-id
: Advanced IPv4 ACL rule number in the range 0 to 65534.
deny
: Defines a deny statement to drop matched packets.
permit
: Defines a permit statement to allow matched packets to pass.
protocol
: Protocol carried by IP. It can be a number in the range 0 to 255, or in
words,
gre
(47),
icmp
(1),
igmp
(2),
ip
,
ipinip
(4),
ospf
(89),
tcp
(6),
udp
(17).
Table 546
Parameters for advanced IPv4 ACL rules
Parameter Function Description
source
{ sour-addr
sour-wildcard |
any
}
Specifies a source
address.
The sour-addr sour-wildcard argument
specifies a source IP address in dotted decimal
notation. Setting the wildcard to a zero
indicates a host address. The
any
keyword
indicates any source IP address.
destination
{ dest-addr
dest-wildcard |
any
}
Specifies a
destination address.
The dest-addr dest-wildcard argument
specifies a destination IP address in dotted
decimal notation. Setting the dest-wildcard to
a zero indicates a host address. The
any
keyword indicates any destination IP address.
precedence
precedence
Specifies an IP
precedence value.
The precedence argument can be a number in
the range 0 to 7, or in words,
routine
,
priority
,
immediate
,
flash
,
flash-override
,
critical
,
internet
, or
network
.
tos
tos
Specifies a ToS
preference.
The tos argument can be a number in the
range 0 to 15, or in words,
max-reliability
(2),
max-throughput
(4),
min-delay
(8),
min-monetary-cost
(1), or
normal
(0).
dscp
dscp
Specifies a DSCP
priority.
The dscp argument can be a number in the
range 0 to 63, or in words,
af11
,
af12
,
af13
,
af21
,
af22
,
af23
,
af31
,
af32
,
af33
,
af41
,
af42
,
af43
,
cs1
,
cs2
,
cs3
,
cs4
,
cs5
,
cs6
,
cs7
,
default
, or
ef
.
logging
Specifies to log
matched packets.
The log provides information about ACL rule
number, whether packets are permitted or
dropped, upper layer protocol that IP carries,
source/destination address, source/destination
port number, and number of packets.
Содержание MSR 20-20
Страница 110: ......
Страница 130: ...130 CHAPTER 4 ATM OC 3C STM 1 INTERFACE CONFIGURATION COMMANDS...
Страница 141: ...141 Sysname system view Sysname interface atm 5 0 Sysname Atm5 0 shdsl wire 4 auto enhanced...
Страница 142: ...142 CHAPTER 5 G SHDSL INTERFACE CONFIGURATION COMMANDS...
Страница 150: ...150 CHAPTER 6 ADSL INTERFACE CONFIGURATION COMMANDS...
Страница 174: ...174 CHAPTER 8 GENERAL ETHERNET INTERFACE CONFIGURATION COMMANDS...
Страница 186: ...186 CHAPTER 9 CONFIGURATION COMMANDS FOR ETHERNET INTERFACES IN BRIDGE MODE...
Страница 288: ...288 CHAPTER 17 FUNDAMENTAL CT3 INTERFACE CONFIGURATION COMMANDS...
Страница 290: ...290 CHAPTER 18 ISDN BRI INTERFACE CONFIGURATION COMMANDS...
Страница 336: ...336 CHAPTER 20 DCC CONFIGURATION COMMANDS...
Страница 410: ...410 CHAPTER 22 FRAME RELAY CONFIGURATION COMMANDS Sysname system view Sysname x25 template vofr Sysname x25 vofr...
Страница 418: ...418 CHAPTER 24 GVRP CONFIGURATION COMMANDS...
Страница 502: ...502 CHAPTER 30 PORT MIRRORING CONFIGURATION COMMANDS...
Страница 532: ...532 CHAPTER 32 PPP LINK EFFICIENCY MECHANISM CONFIGURATION COMMANDS...
Страница 538: ...538 CHAPTER 33 PPPOE SERVER CONFIGURATION COMMANDS...
Страница 548: ...548 CHAPTER 35 PPP DEBUGGING COMMANDS...
Страница 596: ...596 CHAPTER 37 ISDN CONFIGURATION COMMANDS...
Страница 630: ...630 CHAPTER 38 MSTP CONFIGURATION COMMANDS...
Страница 638: ...638 CHAPTER 39 VLAN CONFIGURATION COMMANDS...
Страница 652: ...652 CHAPTER 41 VOICE VLAN CONFIGURATION COMMANDS...
Страница 670: ...670 CHAPTER 44 LOGICAL INTERFACE CONFIGURATION COMMANDS...
Страница 688: ...688 CHAPTER 45 CPOS INTERFACE CONFIGURATION COMMANDS...
Страница 696: ...696 CHAPTER 46 ARP CONFIGURATION COMMANDS...
Страница 728: ...728 CHAPTER 51 DHCP SERVER CONFIGURATION COMMANDS...
Страница 742: ...742 CHAPTER 52 DHCP RELAY AGENT CONFIGURATION COMMANDS...
Страница 746: ...746 CHAPTER 53 DHCP CLIENT CONFIGURATION COMMANDS...
Страница 750: ...750 CHAPTER 54 DHCP SNOOPING CONFIGURATION COMMANDS...
Страница 772: ...772 CHAPTER 57 DNS CONFIGURATION COMMANDS...
Страница 786: ...786 CHAPTER 59 IP ADDRESSING CONFIGURATION COMMANDS...
Страница 806: ...806 CHAPTER 60 IP PERFORMANCE CONFIGURATION COMMANDS...
Страница 818: ...818 CHAPTER 61 IP UNICAST POLICY ROUTING CONFIGURATION COMMANDS...
Страница 822: ...822 CHAPTER 62 UDP HELPER CONFIGURATION COMMANDS...
Страница 824: ...824 CHAPTER 63 URPF CONFIGURATION COMMANDS...
Страница 828: ...828 CHAPTER 64 FAST FORWARDING COMMANDS...
Страница 880: ...880 CHAPTER 67 DUAL STACK CONFIGURATION COMMANDS...
Страница 888: ...888 CHAPTER 68 TUNNELING CONFIGURATION COMMANDS...
Страница 928: ...928 CHAPTER 70 TERMINAL ACCESS CONFIGURATION COMMANDS...
Страница 1014: ...1014 CHAPTER 72 BGP CONFIGURATION COMMANDS...
Страница 1088: ...1088 CHAPTER 74 IS IS CONFIGURATION COMMANDS...
Страница 1106: ...1106 CHAPTER 75 IS IS DEBUGGING COMMANDS...
Страница 1212: ...1212 CHAPTER 79 IPV4 ROUTING POLICY CONFIGURATION COMMANDS...
Страница 1268: ...1268 CHAPTER 82 IPV6 BGP CONFIGURATION COMMANDS...
Страница 1324: ...1324 CHAPTER 85 IPV6 RIPNG CONFIGURATION COMMANDS...
Страница 1364: ...1364 CHAPTER 88 IGMP CONFIGURATION COMMANDS...
Страница 1430: ...1430 CHAPTER 90 PIM CONFIGURATION COMMANDS...
Страница 1504: ...1504 CHAPTER 93 IPV6 PIM CONFIGURATION COMMANDS...
Страница 1644: ...1644 CHAPTER 96 MPLS TE CONFIGURATION COMMANDS...
Страница 1670: ...1670 CHAPTER 97 MPLS L2VPN CONFIGURATION COMMANDS...
Страница 1742: ...1742 CHAPTER 101 IPSEC PROFILE CONFIGURATION COMMANDS...
Страница 1774: ...1774 CHAPTER 105 TRAFFIC POLICING TP CONFIGURATION COMMANDS...
Страница 1778: ...1778 CHAPTER 106 TRAFFIC SHAPING CONFIGURATION COMMANDS...
Страница 1782: ...1782 CHAPTER 107 LINE RATE CONFIGURATION COMMANDS...
Страница 1807: ...1807 Sysname system view Sysname qos policy user1 Sysname qospolicy user1...
Страница 1808: ...1808 CHAPTER 110 DEFINING POLICY COMMANDS...
Страница 1810: ...1810 CHAPTER 111 FIFO QUEUING CONFIGURATION COMMANDS...
Страница 1836: ...1836 CHAPTER 116 RTP PRIORITY QUEUE CONFIGURATION COMMANDS...
Страница 1838: ...1838 CHAPTER 117 QOS TOKEN CONFIGURATION COMMANDS...
Страница 1842: ...1842 CHAPTER 118 PRIORITY MAPPING TABLE CONFIGURATION COMMANDS...
Страница 1844: ...1844 CHAPTER 119 PORT PRIORITY CONFIGURATION COMMANDS...
Страница 1852: ...1852 CHAPTER 121 WRED CONFIGURATION COMMANDS...
Страница 1860: ...1860 CHAPTER 123 MPLS QOS CONFIGURATION COMMANDS...
Страница 1874: ...1874 CHAPTER 124 DAR CONFIGURATION COMMANDS...
Страница 1947: ...1947 Sysname system view Sysname local user user1 Sysname luser user1 work directory cf...
Страница 1948: ...1948 CHAPTER 127 AAA CONFIGURATION COMMANDS...
Страница 1990: ...1990 CHAPTER 129 HWTACACS CONFIGURATION COMMANDS...
Страница 2008: ...2008 CHAPTER 131 ASPF CONFIGURATION COMMANDS...
Страница 2080: ...2080 CHAPTER 135 PORTAL CONFIGURATION COMMANDS...
Страница 2086: ...2086 CHAPTER 137 COMMON CONFIGURATION COMMANDS...
Страница 2102: ...2102 CHAPTER 138 IPV4 ACL CONFIGURATION COMMANDS...
Страница 2118: ...2118 CHAPTER 139 IPV6 ACL CONFIGURATION COMMANDS...
Страница 2200: ...2200 CHAPTER 142 SSH2 0 CONFIGURATION COMMANDS...
Страница 2292: ...2292 CHAPTER 150 NQA SERVER CONFIGURATION COMMANDS Sysname system view Sysname nqa server udp echo 169 254 10 2 9000...
Страница 2314: ...2314 CHAPTER 152 NTP CONFIGURATION COMMANDS...
Страница 2328: ...2328 CHAPTER 153 RMON CONFIGURATION COMMANDS...
Страница 2350: ...2350 CHAPTER 154 SNMP CONFIGURATION COMMANDS...
Страница 2368: ...2368 CHAPTER 156 CONFIGURATION FILE MANAGEMENT COMMANDS...
Страница 2390: ...2390 CHAPTER 158 FTP CLIENT CONFIGURATION COMMANDS...
Страница 2396: ...2396 CHAPTER 159 TFTP CLIENT CONFIGURATION COMMANDS...
Страница 2476: ...2476 CHAPTER 164 USER INTERFACE CONFIGURATION COMMANDS Sysname system view Sysname user interface vty 0 3 Sysname ui vty0 3...
Страница 2484: ...2484 CHAPTER 165 MAC ADDRESS TABLE MANAGEMENT CONFIGURATION COMMANDS...
Страница 2646: ...2646 CHAPTER 174 DIAL PLAN CONFIGURATION COMMANDS...
Страница 2710: ...2710 CHAPTER 178 SIP CONFIGURATION COMMANDS...
Страница 2720: ...2720 CHAPTER 179 VOFR CONFIGURATION COMMANDS...