IPv4 Access Control Lists (ACLs)
Overview of Options for Applying IPv4 ACLs on the Switch
Table 9-2.
Command Summary for IPv4 Extended ACLs
Action
Command(s)
Page
Create an Extended,
Named
ACL
or
Add an ACE to the End
of an Existing,
Extended ACL
ProCurve(config)# ip access-list extended <
name-str
| 100-199 >
ProCurve(config-std-nacl)# < deny | permit >
< ip |
ip-protocol
|
ip-protocol-nbr
>
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
1
< any | host <
DA
> |
DA
/< mask-length > |
DA
<
mask
>>
1
< tcp | udp >
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
1
[
comparison
-
operator
<
value
>]
< any | host <
DA
> |
DA
/< mask-length > |
DA
<
mask
>>
1
[
comparison
-
operator
<
value
>]
[established]
< igmp >
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
1
< any | host <
DA
> |
DA
/< mask-length > |
DA
<
mask
>>
1
[
igmp-packet-type
]
< icmp >
< any | host <
SA
> |
SA
/< mask-length > |
SA
<
mask
>>
1
< any | host <
DA
> |
DA
/< mask-length > |
DA
<
mask
>>
1
[ [< 0 - 255 > [ 0 - 255 ] ] |
icmp-message
]
[precedence <
priority
>]
[tos <
tos- setting
>]
[log]
2
Create an Extended,
ProCurve(config)# access-list < 100-199 > < deny | permit >
Numbered
ACL
<
ip-options
|
tcp/udp-options
|
igmp-options
|
icmp-options
>
or
[precedence <
priority
>]
Add an ACE to the End
[tos <
tos- setting
>]
of an Existing,
[log]
2
Numbered
ACL
Note:
Uses the same IP, TCP/UDP, IGMP, and ICMP options as shown above for
“Create an Extended, Named ACL”.
Insert an ACE by
ProCurve(config)# ip access-list extended <
name-str
| 100-199 >
Assigning a Sequence
ProCurve(config-ext-nacl)# 1-2147483647 < deny | permit >
Number
Uses the options shown above for “Create an Extended, Named ACL”.
Delete an ACE by
ProCurve(config)# ip access-list extended <
name-str
| 100-199 >
Specifying Its
ProCurve(config-std-nacl)# no < 1-2147483647 >
Sequence Number
Resequence the ACEs
ProCurve(config)# ip access-list resequence <
name-str
| 100-199 >
in an ACL
< 1-2147483647 > < 1-2147483646 >
1
The mask can be in either dotted-decimal notation (such as 0.0.15.255) or CIDR notation (such as /20).
2
The [ log ] function applies only to “deny” ACLs, and generates a message only when there is a “deny” match.
9-8
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...