10-76
IPv4 Access Control Lists (ACLs)
Configuring Extended ACLs
< deny | permit >
Specifies whether to deny (
drop
) or permit (forward) a packet
that matches the criteria specified in the ACE, as described
below.
< ip |
ip-protocol
|
ip-protocol-nbr
>
Specifies the packet protocol type required for a match. An
extended ACL must include one of the following:
•
ip
—
any IPv4 packet.
•
ip-protocol
—
any one of the following IPv4 protocol names:
ip-in-ip
ipv6-in-ip gre
esp
ah
ospf
pim
vrrp
sctp
tcp*
udp*
icmp*
igmp*
•
ip-protocol-nbr
—
the protocol number of an IPv4 packet type,
such as “8” for Exterior Gateway Protocol or 121 for Simple
Message Protocol. (For a listing of IPv4 protocol numbers
and their corresponding protocol names, refer to the IANA
“Protocol Number Assignment Services” at www.iana.com.)
(Range: 0 - 255)
*
For TCP, UDP, ICMP, and IGMP, additional criteria can be
specified, as described later in this section.
< any | host <
SA
> |
SA/mask-length
|
SA < mask >
>
In an extended ACL, this parameter defines the source address
(SA) that a packet must carry in order to have a match with
the ACE.
•
any
—
Specifies all inbound IPv4 packets.
•
host
<
SA
> —
Specifies only inbound IPv4 packets from a
single address. Use this option when you want to match only
the IPv4 packets from a single source address.
•
SA
/
mask-length
or
SA < mask >
—
Specifies packets received
from an SA, where the SA is either a subnet or a group of
IPv4 addresses. The mask can be in either dotted-decimal
format or CIDR format with the number of significant bits.
Refer to “Using CIDR Notation To Enter the IPv4 ACL Mask”
on page 10-49.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......