CLI Reference Guide
ACL Configuration Commands
Commands
show access-lists
View the extended expert ACL.
Platform
Description
This command is supported only in 10.4 (3b16), 10.4 (3b17), 10.4 (5b1) and later versions.
ip access-group
Use this command to apply a specific ACL to an interface. The
no
form of this command cancels the
application.
ip access-group
{
id
|
name
} {
in
|
out
} [
unreflect
|
reflect
]
no ip access-group
{
id
|
name
} {
in
|
out
}
Parameter
Description
Parameter
Description
id
ID of the IP ACL (1 to 199, 1300 to 2699)
name
Name of the IP ACL
in
Filter the incoming packets of the interface.
out
Filter the outgoing packets of the interface.
unreflect
Disable the Reflexive-ACL. (Working principle of the reflexive ACL: a.
A router generates a temporary access list automatically based on
layer-3 and layer-4 information of original traffic of the intranet. The
temporary access list is created based on the following rules:
Protocol unchanged, source-IP and destination-IP are strictly
exchanged with each other, and source-port and destination-port are
strictly exchanged with each other. b. Only when the layer-3 and
layer-4 information of the returned flow strictly matches with the
previous layer-3 and layer-4 information of the temporary access list
created based on outbound traffic, the router will permit the flow to
enter the intranet.)
reflect
Enable the Reflexive-ACL.
Defaults
No ACL is applied on the interface.
Command
mode
Interface configuration mode.
Usage Guide
Use the
ip access-group
command to apply the specified ACL to the interface, when the firewall is
enabled.
Configuration
Examples
The following example applies the ACL 120 on the fastEthernet0/0 to filter the incoming packets:
Ruijie(config)# interface fastEthernet 0/0
Ruijie(config-if)# ip access-group 120 in
Содержание RG-S2600G-I Series
Страница 1: ...1 CLI Reference Guide RG S2600G I Series Switches RGOS 10 4 3b16...
Страница 5: ...5...
Страница 192: ...CLI ReferenceInterface Configuration Commands Interface Configuration Commands Platform Description...
Страница 452: ...CLI Reference DHCP Configuration Commands commands clear ip dhcp server statistics Delete the DHCP server statistics...
Страница 505: ...CLI Reference TCP Configuration Commands Related commands Command Description...
Страница 513: ...CLI Reference IPv4 REF Configuration Commands Platform description N A Command history Version Description...
Страница 514: ...IP Routing Configuration Commands 1 IP Routing Configuration Commands...
Страница 527: ...Multicast Configuration Commands 1 IGMP Snooping Configuration Commands 2 MLD Snooping Configuration Commands...
Страница 642: ...CLI Reference TACACS Configuration Commands host...
Страница 652: ...CLI Reference 802 1X Configuration Commands Ruijie config if end...
Страница 744: ...CLI Reference CPU Protection Configuration Commands Caution This command is not supported on S3760 series...
Страница 773: ...CLI Reference IPSource Guard Configuration Commands Platform description This command is supported on all switches...
Страница 776: ...CLI Reference ND Snooping Configuration Commands...
Страница 901: ...CLI Reference NFPP Configuration Commands...
Страница 902: ...ACL QOS Configuration Commands 1 ACL Configuration Commands 2 QoS Configuration Commands...
Страница 999: ...CLI Reference RLDP Configuration Command Command mode Privileged EXEC mode...
Страница 1004: ...CLI Reference DLDP Configuration Commands Ruijie config if FastEthernet 0 0 clear dldp 20 1 1 1 10 1 1 1...
Страница 1005: ...CLI Reference DLDP Configuration Commands...
Страница 1146: ...CLI Reference VSU Configuration Commands Examples Ruijie vsu conver to stack Related Commands Command Description N A N A...
Страница 1191: ...CLI Reference Guide RSPAN Configuration Commands Platform Description N A...
Страница 1192: ...CLI Reference Guide...