S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
33-7
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 33 Configuring IPv4 and IPv6 Access Control Lists
Configuring IPv4-ACLs or IPv6-ACLs
To use the operand and port options for an IPv6-ACL, follow these steps:
Adding IP Filters to an Existing IPv4-ACL or IPv6-ACL
After you create an IPv4-ACL or an IPv6-ACL, you can add subsequent IP filters at the end of the
IPv4-ACL or the IPv6-ACL. You cannot insert filters in the middle of an IPv4-ACL or an IPv6-ACL.
Each configured entry is automatically added to the end of a IPv4-ACL or a IPv6-ACL.
To add entries to an existing IPv4-ACL, follow these steps:
To add entries to an existing IPv6-
ACL
, follow these steps
:
Removing IP Filters from an Existing IPv4-ACL or IPv6-ACL
To remove configured entries from an IPv4-ACL, follow these steps:
Command
Purpose
Step 1
switch#
config t
Enters configuration mode.
Step 2
switch(config)#
ip access-list List2 deny tcp
2001:0DB8:800:200C::/64 eq port 5 any
Denies TCP traffic from
2001:0DB8:800:200C::/64 through source
port 5 to any destination.
Command
Purpose
Step 1
switch#
config t
Enters configuration mode.
Step 2
switch(config)#
ip access-list List1 permit tcp
10.1.1.2 0.0.0.0 172.16.1.1 0.0.0.0 eq port telnet
Permits TCP for Telnet traffic.
Step 3
switch(config)#
ip access-list List1 permit tcp
10.1.1.2 0.0.0.0 172.16.1.1 0.0.0.0 eq port http
Permits TCP for HTTP traffic.
Step 4
switch(config)#
ip access-list List1 permit udp
10.1.1.2 0.0.0.0 172.16.1.1 0.0.0.0
Permits UDP for all traffic.
Command
Purpose
Step 1
switch#
config t
switch(config)#
Enters configuration mode.
Step 2
switch(config)#
ipv6 access-list List2
switch(config-ipv6-acl)#
Configures an IPv6-ACL and enters
IPv6-ACL configuration submode.
Step 3
switch(config-ipv6-acl)#
permit ip
2001:0DB8:800:200C::/64 2001:0DB8:800:2010::/64 eq
23
Permits TCP for Telnet traffic.
Step 4
switch(config-ipv6-acl)#
permit tcp
2001:0DB8:800:200C::/64 2001:0DB8:800:2010::/64 eq
143
Permits TCP for HTTP traffic.
Step 5
switch(config-ipv6-acl)#
permit udp
2001:0DB8:800:200C::/64 2001:0DB8:800:2010::/64
Permits UDP for all traffic.
Command
Purpose
Step 1
switch#
config t
Enters configuration mode.
Содержание 9124 - Cisco MDS Fabric Switch
Страница 76: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 122: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 328: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 482: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 733: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 5 Security ...
Страница 734: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 957: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 6 IP Services ...
Страница 958: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1182: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1214: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1307: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 9 Traffic Management ...
Страница 1308: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1331: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 1 0 Troubleshooting ...
Страница 1332: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...