10-68
IPv4 Access Control Lists (ACLs)
Configuring Extended ACLs
Comparison Operators:
•
eq
<
tcp/udp-port-nbr
>
—
“Equal To”; to have a match with the
ACE entry, the TCP or UDP source port number in a packet
must be equal to <
tcp/udp-port-nbr
>.
•
gt
<
tcp/udp-port-nbr
>
—
“Greater Than”; to have a match with
the ACE entry, the TCP or UDP source port number in a
packet must be greater than <
tcp/udp-port-nbr
>.
•
lt
<
tcp/udp-port-nbr
>
—
“Less Than”; to have a match with the
ACE entry, the TCP or UDP source port number in a packet
must be less than <
tcp/udp-port-nbr
>.
•
neq
<
tcp/udp-port-nbr
>
—
“Not Equal”; to have a match with
the ACE entry, the TCP or UDP source port number in a
packet must not be equal to
< tcp/udp-port-nbr >
.
•
range
< start-port-nbr > < end-port-nbr >
—
For a match with the
ACE entry, the TCP or UDP source-port number in a packet
must be in the range
<
start-port-nbr >
< end-port-nbr
>
.
Port Number or Well-Known Port Name:
Use the TCP or UDP port number required by your appli-
cation. The switch also accepts these well-known TCP or
UDP port names as an alternative to their port numbers:
•
TCP
:
bgp, dns, ftp, http, imap4, ldap, nntp, pop2, pop3, smtp, ssl,
telnet
•
UDP
:
bootpc, bootps, dns, ntp, radius, radius-old, rip, snmp,
snmp-trap, tftp
To list the above names, press the
[Shift] [?]
key combination
after entering an operator. For a comprehensive listing of
port numbers, visit www.iana.org/assignments/port-
numbers.
[
comparison
-
operator
<
tcp-dest-port
>] [established]
[
comparison
-
operator
<
udp-dest-port
>]
This option, if used, is entered immediately after the
<
DA
>
entry. To specify a TCP or UDP port number, (1) select a
comparison operator and (2) enter the port number or a well-
known port name.
Comparison Operators and Well-Known Port Names —
These are the same as are used with the TCP/UDP source-port
options, and are listed earlier in this command description.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......