121
deny (advance access-list)
Specifies the conditions by which the Advance filter denies access.
Input format
To set or change information:
[
<sequence>
] deny mac {
filter-condition
}[
action-specification
]
[
<sequence>
] deny mac-ip {
filter-condition
}[
action-specification
]
[
<sequence>
] deny mac-ipv6 {
filter-condition
}[
action-specification
]
filter-condition
For
mac {
filter-condition
}
:
This filter condition is used to perform flow detection based on MAC header
conditions.
mac {
<source mac>
<source mac mask>
| host
<source mac>
| any}
{
<destination mac>
<destination mac mask>
| host
<destination mac>
| any
| bpdu | cdp | lacp | lldp | oadp | pvst-plus-bpdu | slow-protocol}
[
<ethernet type>
][vlan {
<vlan id>
|
<vlan id list name>
}] [user-priority
<priority>
][{ctag-untagged | [ctag-user-priority
<priority>
]
[ctag-vlan
<vlan id>
]}]
For
mac-ip {
filter-condition
}
:
This filter condition is used to perform flow detection based on MAC header
conditions, IPv4 header conditions, or Layer 4 header conditions.
-
When "packet is not fragmented" is a condition, and the upper-layer
protocol is other than TCP, UDP, ICMP, and IGMP
mac-ip {
<source mac>
<source mac mask>
| host
<source mac>
|
any} {
<destination mac>
<destination mac mask>
| host
<destination
mac>
| any | bpdu | cdp | lacp | lldp | oadp | pvst-plus-bpdu
| slow-protocol} {ip |
<protocol>
} {{
<source ipv4>
|
own-address}
<source ipv4 wildcard>
| host {
<source ipv4>
|
own-address} | any | own | range-address
<source ipv4 start>
<source ipv4 end>
} {{
<destination ipv4>
| own-address}
<destination ipv4 wildcard>
| host {
<destination ipv4>
|
own-address} | any | own | range-address
<destination ipv4 start>
<destination ipv4 end>
} [{[tos
<tos>
] [precedence
<precedence>
]
| dscp
<dscp>
}] [vlan {
<vlan id>
|
<vlan id list name>
}]
[user-priority
<priority>
][{ctag-untagged |
[ctag-user-priority
<priority>
] [ctag-vlan
<vlan id>
]}]
-
When "packet is not fragmented" is a condition, and the upper-layer
protocol is TCP
mac-ip {
<source mac>
<source mac mask>
| host
<source mac>
|
any} {
<destination mac>
<destination mac mask>
| host
<destination
mac>
| any | bpdu | cdp | lacp | lldp | oadp | pvst-plus-bpdu
| slow-protocol} tcp {{
<source ipv4>
| own-address}
<source
ipv4 wildcard>
| host {
<source ipv4>
| own-address} | any | own
| range-address
<source ipv4 start>
<source ipv4 end>
} [{{eq |
neq}
<source port>
| range
<source port start>
<source port end>
}]
{{
<destination ipv4>
| own-address}
<destination ipv4 wildcard>
|
host {
<destination ipv4>
| own-address} | any | own |
range-address
<destination ipv4 start>
<destination ipv4 end>
}
[{{eq | neq}
<destination port>
| range
<destination port start>
<destination port end>
}] [{[established] | [{ack | +ack | -ack}]
[{fin | +fin | -fin}] [{psh | +psh | -psh}] [{rst | +rst |
-rst}] [{syn | +syn | -syn}] [{urg | +urg | -urg}]}] [{[tos
Содержание GX1000-SMC013X
Страница 94: ...94 5 Configuration Guide 5 1 Base Software Configuration Guide ...
Страница 105: ...105 7 Access Lists 7 1 Access lists ...
Страница 153: ...153 8 Policy Based Switching 8 1 Policy based switching ...
Страница 165: ...165 9 Policy Based Routing 9 1 Policy based routing ...
Страница 177: ...177 Figure 10 1 Overview of mode transitions ...
Страница 188: ...188 14 Configuration Command Reference 14 1 Reading the configuration command reference 14 2 SNMP 14 3 SP functionality ...
Страница 208: ...208 16 Message and Log Reference 16 1 Operation messages and logs 16 2 Device Failure and Event Information ...
Страница 213: ...213 17 MIB Reference 17 1 Private MIBs 17 2 Supported MIB Traps ...
Страница 224: ...224 19 1 Starting the device For details see 5 1 Login procedures in the Base Software Configuration Guide ...
Страница 229: ...229 H W BOOT 11 44 MISC 1 0 SPCT 0 34 10 The updating of the SP files is finished ...
Страница 448: ...448 27 Notes This chapter provides notes on using the WAN acceleration functionality 27 1 Note ...
Страница 451: ...451 28 Additional Information ...