Access Control List Commands
4-161
4
specified source IP address, and then compared with the address for each IP
packet entering the port(s) to which this ACL has been assigned.
• The following control codes may be specified:
- 1 (fin) – Finish
- 2 (syn) – Synchronize
- 4 (rst) – Reset
- 8 (psh) – Push
- 16 (ack) – Acknowledgement
- 32 (urg) – Urgent pointer
To define more than one control code, set the equivalent binary bit to “1” to
indicate the required codes. For example, to set both SYN and ACK valid, use
“control-code 18”
Example
This example accepts any incoming packets if the source address is within subnet
10.7.1.x. For example, if the rule is matched; i.e., the rule (10.7.1.0 & 255.255.255.0)
equals the masked address (10.7.1.2 & 255.255.255.0), the packet passes through.
This allows TCP packets from class C addresses 192.168.1.0 to any destination
address when set for destination TCP port 80 (i.e., HTTP).
This permits all TCP packets from class C addresses 192.168.1.0 with the TCP
control code set to “SYN.”
Related Commands
access-list ip (4-158)
show ip access-list
This command displays the rules for configured IP ACLs.
Syntax
show ip access-list
{
standard
|
extended
} [
acl_name
]
•
standard
– Specifies a standard IP ACL.
•
extended
– Specifies an extended IP ACL.
•
acl_name
– Name of the ACL. (Maximum length: 16 characters)
Console(config-ext-acl)#permit 10.7.1.1 255.255.255.0 any
Console(config-ext-acl)#
Console(config-ext-acl)#permit 192.168.1.0 255.255.255.0 any
destination-port 80
Console(config-ext-acl)#
Console(config-ext-acl)#permit tcp 192.168.1.0 255.255.255.0 any
control-flag 2
Console(config-ext-acl)#
Содержание JetNet 5228G Series
Страница 3: ...www edge core com 2 24FE 4G Layer 2 4 Ethernet Switch Management Guide V1 1...
Страница 24: ...Tables xx...
Страница 310: ...Configuring the Switch 3 264 3...
Страница 636: ...Command Line Interface 4 326 4...
Страница 650: ...Glossary Glossary 8...
Страница 656: ...Index 6 Index...
Страница 657: ......
Страница 658: ......