10-5
IPv4 Access Control Lists (ACLs)
Overview of Options for Applying IPv4 ACLs on the Switch
Command Summary for Standard IPv4 ACLs
Action
Command(s)
Page
Create a Standard,
Named
ACL
or
Add an ACE to the End
of an Existing Stan-
dard,
Named
ACL
HP Switch(config)# ip access-list standard <
name-str >
HP Switch(config-std-nacl)# < deny | permit >
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
1
[log]
2
Create a Standard,
Numbered
ACL
or
Add an ACE to the End
of an Existing
Standard,
Numbered
ACL
HP Switch(config)# access-list < 1-99 > < deny | permit >
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
[log]
2
Use a Sequence
Number To Insert an
ACE in a Standard ACL
HP Switch(config)# ip access-list standard <
name-str
| 1-99 >
HP Switch(config-std-nacl)# 1-2147483647 < deny | permit >
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
1
[log]
2
Use an ACE’s
Sequence Number To
Delete the ACE from a
Standard ACL
HP Switch(config)# ip access-list standard <
name-str
| 1-99 >
HP Switch(config-std-nacl)# no < 1-2147483647 >
Resequence the ACEs
in a Standard ACL
HP Switch(config)# ip access-list resequence <
name-str
| 1-99 > < 1-2147483647 >
< 1-2147483646 >
Enter or Remove a
Remark from a
Standard ACL
HP Switch(config)# ip access-list standard <
name-str
| 1-99 >
HP Switch(config-ext-nacl)# [ remark <
remark-str
> | no < 1-2147483647 > remark ]
For numbered, standard ACLs only, the following
remark
commands can be
substituted for the above:
HP Switch(config)# access-list < 1 - 99 > remark < remark-str >
HP Switch(config)# [no] access-list < 1 - 99 > remark
Delete a Standard ACL
HP Switch(config)# no ip access-list standard <
name-str
| 1-99 >
For numbered, standard ACLs, the following command can be substituted for the
above:
HP Switch(config)# access-list < 1 - 99 > remark < remark-str >
1
The mask can be in either dotted-decimal notation (such as 0.0.15.255) or CIDR notation (such as /20).
2
The [ log ] function applies only to “deny” ACLs, and generates a message only when there is a “deny” match.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......