IPv4 Access Control Lists (ACLs)
Editing an Existing ACL
Inserting Remarks and Related ACEs Within an Existing List.
To
insert an ACE with a remark within an ACL by specifying a sequence number,
insert the numbered remark first, then, using the same sequence number,
insert the ACE. (This operation applies only to ACLs accessed using the
“Named-ACL” (
nacl
) context.) For example:
ProCurve(config-std-nacl)# 15 remark "HOST 10.10.10.21"
Inserting a remark/ACE pair with
ProCurve(config-std-nacl)# 15 permit host 10.10.10.21
the same sequence number
requires that the remark (with
ProCurve(config-std-nacl)# show run
the desired sequence number)
ip access-list standard "My-List"
be inserted
before
the ACE with
10 permit 10.10.10.15 0.0.0.0
the same number.
15 remark "HOST 10.10.10.21"
15 permit 10.10.10.21 0.0.0.0
20 deny 10.10.10.1 0.0.0.255
30 remark "HOST-10.20.10.34"
30 permit 10.20.10.34 0.0.0.0
exit
Figure 9-24. Example of Inserting a Remark
Inserting a Remark for an ACE that Already Exists in an ACL.
If a
sequence number is already assigned to an ACE in a list, you cannot insert a
remark by assigning it to the same number. (To configure a remark with the
same number as a given ACE, the remark must be configured first.) To assign
a remark to the same number as an existing ACE:
1. Delete the ACE.
2. Configure the remark with the number you want assigned to the pair.
3. Re-Enter the deleted ACE with the number used to enter the remark.
Removing a Remark from an Existing ACE.
If you want to remove a
remark, but want to retain the ACE, do the following:
1. Use the Named ACL context to enter the ACL.
2. Using
show run
or
show access-list
< list-name >
, note the sequence number
and content of the ACE having a remark you want to remove.
3. Delete the ACE.
4. Using the same sequence number, re-enter the ACE.
9-83
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...