![Quanta Computer QuantaMesh Скачать руководство пользователя страница 588](http://html1.mh-extra.com/html/quanta-computer/quantamesh/quantamesh_user-manual_770072588.webp)
UANTA COMPUTER INC.
Layer 2/3/4 Managed Switch
QuantaMesh | Switching Commands
588
5.21.2.5 access-list
This command creates an Access Control List (ACL) that is identified by the parameter.
Syntax
access-list {(<1-99> {deny | permit} {every | <srcip> <srcm ask>}) | ( {<100-199> {deny | permit} {every
| {{eigrp| gre | icmp | igmp | ip | ipinip | ospf | pim | tcp | udp | <number>} {srcip srcmask | any | host
srcip} [{range {portkey|startport} {portkey|endport} | {eq | neq | lt | gt} {portkey|0-65535} {dstip dstmask |
any | host dstip} [{range {portkey|startport} {portkey|endport} | {eq | neq | lt | gt} {portkey|0-65535}] [flag
[+fin | -fin] [+syn | -syn] [+rst | -rst] [+psh | -psh] [+ack | -ack] [+urg | -urg] [established]] {[fragments]
[precedence <precedence>] | [tos <tos> <tosmask>] | [dscp <dscp>] [log] [time-range
time-range-name] [assign-queue <queue-id>] [{mirror | redirect} {<slot/port> | port-channel
<portchannel-id>}] [{redirectExtAgent <agent-id>}] [{rate-limit rate burst-size}] [<rule-id>]}}}})}
<accesslistnumber> - The ACL number is an integer from 1 to 199. The range 1 to 99 is for the
normal ACL List and 100 to 199 is for the extended ACL List.
permit or deny - The ACL rule is created with two options. The protocol to filter for an ACL rule is
specified by giving the protocol to be used like icmp ,igmp ,ip ,tcp, udp. The command specifies a
source ip address and source mask for match condition of the ACL rule specified by the srcip and
srcmask parameters. The source layer 4 port match condition for the ACL rule is specified by the
port key parameter.
<portkey> - uses a single keyword notation and currently has the values of domain, echo, ftp,
ftpdata, http, smtp, snmp, telnet, tftp, and www. Each of these values translates into its
equivalent port number, which is used as both the start and end of a port range. The command
specifies a destination ip address and destination mask for match condition of the ACL rule specified
by the dstip and dstmask parameters. The command specifies the TOS for an ACL rule depending
on a match of precedence or DSCP values using the parameters tos, tosmask, dscp.
[time-range time-range-name] - Allows imposing time limitation on the ACL rule as defined by the
parameter time-range-name. If a time range with the specified name does not exist and the ACL
containing this ACL rule is applied to an interface or bound to a VLAN, then the ACL rule is applied
immediately. If a time range with specified name exists and the ACL containing this ACL rule is
applied to an interface or bound to a VLAN, then the ACL rule is applied when the time-range with
specified name becomes active. The ACL rule is removed when the time-range with specified name
becomes inactive.
[{range {portkey|startport} {portkey|endport}} | {eq | neq | lt | gt} {portkey|0-65535}] – Specifies
the layer 4 port match confition for the IP ACL rule. Note: This option is available only if the protocol
is tcp or udp.
flag – Specifies that the IP ACL rule matches on the TCP flags. Note: This opetion is available only if
the protol is tcp.
fragments – Spectifies that the IP ACL rule matches on fragmented IP packets.
[rate-limit rate burst-size] – Specifies the allowed rate of traffic as per the configured rate in kbps,
and burst –size in kbytes.
[redirectExtAgent agent-id] - allows matching flow packets to be sent to external applications
running alongside ICOS on a control CPU. agent-id is a unique identifier for the external receive
client application.
Содержание QuantaMesh
Страница 17: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Introduction 17 ...
Страница 224: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 224 ...
Страница 226: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 226 ...
Страница 229: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 229 ...
Страница 411: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 411 ...
Страница 514: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 514 Global Config ...
Страница 626: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 626 Command Mode Global Config ...
Страница 631: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 631 ...
Страница 636: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 636 ...
Страница 644: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 644 Global Config ...
Страница 862: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh IP Multicast Commands 862 ...
Страница 881: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh IP Multicast Commands 881 None Command Mode Global Config ...
Страница 912: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh IPv6 Commands 912 8 3 1 8 ...