Chapter 4: Feature Configuration - CLI
Featuring Configuration – CLI
NGSME16T2H User Manual | 223
digit) or 'any'
<dmac> : Destination MAC address
('xx-xx-xx-xx-xx-xx' or 'xx.xx.xx.xx.xx.xx' or 'xxxxxxxxxxxx', x is
a hexadecimal digit) or 'any'
arp : ARP keyword
<sip> : Source IP address (a.b.c.d/n) or 'any'
<dip> : Destination IP address (a.b.c.d/n) or 'any'
<arp_opcode> : ARP operation code: any|arp|rarp|other
<arp_flags> : ARP flags: request|smac|tmac|len|ip|ether
[0|1|any]
ip : IP keyword
<protocol> : IP protocol number (0-255) or 'any'
<ip_flags> : IP flags: ttl|options|fragment [0|1|any]
icmp : ICMP keyword
<icmp_type> : ICMP type number (0-255) or 'any'
<icmp_code> : ICMP code number (0-255) or 'any'
udp : UDP keyword
<sport> : Source UDP/TCP port range (0-65535) or
'any'
<dport> : Destination UDP/TCP port range (0-65535)
or 'any'
tcp : TCP keyword
<tcp_flags> : TCP flags: fin|syn|rst|psh|ack|urg [0|1|any]
permit : Permit forwarding (default)
deny : Deny forwarding
<rate_limiter> : Rate limiter number (1-15) or 'disable'
<port_redirect> : Port list for copy of frames or 'disable'
<mirror> : Mirror of frames: enable|disable
<logging> : System logging of frames: log|log_disable
<shutdown> : Shut down ingress port: shut|shut_disable
Example:
Add one ACE:
Security/Network/ACL>add 2 port 6-10 policy 3 8 ip