8. Access Control List (ACL) Egress Command List
117
8. Access Control List (ACL) Egress
Command List
While "Access Control List (ACL) Commands" filter packets reaching the
Switching Hub, these commands filter packets output from the
Switching Hub.
For overview on filtering, refer to "Access Control List (ACL)
Commands."
Up to 4 profiles and 128 rules per profile can be created.
You can create a port group and specify an ACL target with the group
name and group ID.
create egress_access_profile profile_id <value 1-4> profile_name <name 1-32> [ethernet {vlan
{<hex 0x0-0x0fff>} | source_mac <macmask 000000000000-ffffffffffff> | destination_mac
<macmask 000000000000-ffffffffffff> | 802.1p | ethernet_type} | ip {vlan {<hex 0x0-
0x0fff>} | source_ip_mask <netmask> | destination_ip_mask <netmask> | dscp | [icmp {type
| code} | igmp {type} | tcp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-
0xffff> | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} | udp {src_port_mask <hex 0x0-
0xffff> | dst_port_mask<hex 0x0-0xffff>} | protocol_id_mask <hex 0x0-0xff>
{user_define_mask <hex 0x0-0xffffffff>}]} | ipv6 {class | source_ipv6_mask <ipv6mask> |
destination_ipv6_mask <ipv6mask> | [tcp {src_port_mask <hex 0x0-0xffff> | dst_port_mask
<hex 0x0-0xffff>} | udp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>} |
icmp {type | code}]}]
delete egress_access_profile [profile_id <value 1-4> | profile_name <name 1-32> | all]
config egress_access_profile [profile_id <value 1-4> | profile_name <name 1-32>] [add access_id
[auto_assign | <value 1-128>] [ethernet {[vlan <vlan_name 32> | vlan_id <vlanid 1-4094>]
{mask <hex 0x0-0x0fff>} | source_mac <macaddr> {mask <macmask>} | destination_mac
<macaddr> {mask <macmask>} | 802.1p <value 0-7> | ethernet_type <hex 0x0-0xffff>} | ip
{[vlan <vlan_name 32> | vlan_id <vlanid 1-4094>] {mask <hex 0x0-0x0fff>} | source_ip
<ipaddr> {mask <netmask>} | destination_ip <ipaddr> {mask <netmask>} | dscp <value 0-
63> | [icmp {type <value 0-255> | code <value 0-255>} | igmp {type <value 0-255>} | tcp
{src_port <value 0-65535> {mask <hex 0x0-0xffff>} | dst_port <value 0-65535> {mask <hex
0x0-0xffff>} | flag [all | {urg | ack | psh | rst | syn | fin}]} | udp {src_port <value 0-65535>
{mask <hex 0x0-0xffff>} | dst_port <value 0-65535> {mask <hex 0x0-0xffff>}} | protocol_id
<value 0-255> {user_define <hex 0x0-0xffffffff> {mask <hex 0x0-0xffffffff>}}]} | ipv6 {class
<value 0-255> | source_ipv6 <ipv6addr> {mask <ipv6mask>} | destination_ipv6 <ipv6addr>
{mask <ipv6mask>} | [tcp {src_port <value 0-65535> {mask <hex 0x0-0xffff>} | dst_port
<value 0-65535> {mask <hex 0x0-0xffff>}} | udp {src_port <value 0-65535> {mask <hex 0x0-
0xffff>} | dst_port <value 0-65535> {mask <hex 0x0-0xffff>}} | icmp {type <value 0-255> |
code <value 0-255>}]}] [vlan_based [vlan <vlan_name 32> | vlan_id <vlanid 1-4094>] |
port_group [id <value 1-64> | name <name 16>] | port <port>] [permit {replace_priority_with
<value 0-7> | replace_dscp_with <value 0-63> | counter [enable | disable]} | deny]
{time_range <range_name 32>} | delete access_id <value 1-128>]
show egress_access_profile {[profile_id <value 1-4> | profile_name <name 1-32>]}
show current_config egress_access_profile
ワヰヵユ
ワヰヵユ
Содержание ZEQUO 6400
Страница 158: ...12 Basic IP Commands 159 Zxxx0 admin config ipif System vlan v1 Command config ipif System vlan v1 Success Zxxx0 admin ...
Страница 160: ...12 Basic IP Commands 161 ...
Страница 189: ...17 Command Logging Command List 190 ...
Страница 554: ...49 MAC based Access Control Commands 555 ...
Страница 644: ...58 Network Monitoring Commands 645 Zxxx0 admin clear attack_log Command clear attack_log Success Zxxx0 admin ...
Страница 812: ...69 QoS Commands 813 ...
Страница 839: ...73 SNMPv1 v2 v3 Commands 840 Only Administrator level users can issue this command ...
Страница 962: ...85 Virtual Router Redundancy Protocol VRRP Command List 963 ...
Страница 1050: ...91 System Log Lists 1051 ...