14-17
Usage Guidelines
Use this command to permit traffic between network’s/host’s based on the protocol type selected in the access
list configuration. The following protocols are supported:
•
ip
•
icmp
•
tcp
•
udp
The last ACE in the access list is an implict deny statement.
Whenever the interface receives the packet, its content is checked against all the ACE’s in the ACL. It is
allowed based on the ACL configuration.
•
Filtering on Protocol types tcp/udp allows the user to specify port numbers as filtering criteria.
permit{
tcp|udp
}
{source/source-mask |
host source | any}
[operator source-port]
{destination/destination-
mask | host destination |
any}
[operator destination-port]
[log]
[rule-precedence access-
list-entry precedence]
Use with the
permit
command to allow
tcp or udp
packets.
•
permit – The keyword specifies permit action on an ACL.
•
{
tcp|udp
} – Specify tcp or udp as the protocol.
•
{source/source-mask | host source | any} –
source
is the source IP
address of the network or host in dotted decimal. Source-mask is the
network mask. For example, 10.1.1.10/24 indicates the first 24 bits of the
source IP are used for matching.
•
any
is an abbreviation for source IP of 0.0.0.0 and source-mask bits
equal to 0.
•
host
is an abbreviation for exact source (A.B.C.D) and source-mask
bits equal to 32.
•
[operator source-port] – Valid only for tcp or udp protocols. Valid values
are
eq
and
range
.
•
range – Specify the protocol range (starting and ending protocol
numbers).
•
port – Valid Port number.
•
{destination/destination-mask | host destination | any} – The destination
host IP address or destination network address.
•
[operator destination-port] – Specify the destination port.
•
[log] – Generates log messages when the packet coming from the
interface matches the ACL entry. Log messages are generated only for
router ACLs.
•
[rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.
Содержание RFS7000 Series
Страница 1: ... RFS7000 Series RF Switch CLI Reference Guide ...
Страница 10: ...x RFS7000 Series CLI Reference Guide ...
Страница 30: ...Overview 1 10 ...
Страница 150: ...Overview 3 16 RFS7000 show management Mgmt Interface vlan1 Management access permitted via any vlan interface RFS7000 ...
Страница 196: ...Overview 4 46 ...
Страница 270: ...Overview 5 74 ...
Страница 284: ...Overview 6 14 ...
Страница 294: ...Overview 7 10 ...
Страница 304: ...Overview 8 10 ...
Страница 308: ...Overview 9 4 ...
Страница 338: ...Overview 11 36 ...
Страница 366: ...Overview 12 28 ...
Страница 380: ...Overview 13 14 ...
Страница 404: ...Overview 15 2 terminal Sets terminal line parameters page 15 14 Command Description Ref ...
Страница 434: ...Overview 16 18 ...
Страница 466: ...Overview 17 32 ...
Страница 474: ...Overview 18 8 ...
Страница 504: ...Overview 19 30 ...
Страница 572: ...Overview 20 68 ...
Страница 581: ...21 9 new show alarm log count all new acknowledged severity to limit 1 65535 RFS7000 config sole ...
Страница 584: ...Overview 21 12 ...
Страница 586: ...A 2 RFS7000 Series CLI Reference Guide ...
Страница 587: ......
Страница 588: ...MOTOROLA INC 1303 E ALGONQUIN ROAD SCHAUMBURG IL 60196 http www motorola com 72E 103891 01 Revision A January 2008 ...