IPv4 Access Control Lists (ACLs)
Configuring Extended ACLs
< any | host <
DA
> |
DA/mask
-length |
DA/ < mask
>>
This is the second instance of IPv4 addressing in an extended
ACE. It follows the first (SA) instance, described earlier, and
defines the destination address (DA) that a packet must carry
in order to have a match with the ACE.
•
any
—
Allows routed IPv4 packets to any DA.
•
host
<
DA
> —
Specifies only packets having
DA
as the
destination address. Use this criterion when you want to
match only the IPv4 packets for a single DA.
•
DA
/
mask-length
or
DA< mask > —
Specifies packets intended
for a destination address, where the address is either a
subnet or a group of addresses. The mask format can be in
either dotted-decimal format or CIDR format (number of
significant bits). Refer to “Using CIDR Notation To Enter
the IPv4 ACL Mask” on page 9-43.
DA Mask Application:
The mask is applied to the DA in
the ACL to define which bits in a packet’s DA must exactly
match the DA configured in the ACL and which bits need
not match. See also the above example and note.
[ precedence < 0 - 7 |
precedence-name
>]
This option can be used after the DA to cause the ACE to match
packets with the specified IP precedence value. Values can be
entered as the following IP precedence numbers or alphanu
meric names:
0
or
routine
1
“
priority
2
“
immediate
3
“
flash
4
“
flash-override
5
“
critical
6
“
internet (for internetwork control)
7
“
network (for network control)
Note:
The precedence criteria described in this section are
applied in addition to any other selection criteria configured
in the same ACE.
9-59
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...