Command Reference ACL Commands
1.31 permit
One or multiple
permit
conditions are used to determine whether to forward or discard the packet. In
ACL configuration mode, you can modify the existent ACL or configure according to the protocol
details.
9.
Standard IP ACL
[
sn
]
permit
{
source
source-wildcard
|
host
source
|
any
| interface
idx
} [
time-range
tm-range-name
] [
log
]
10. Extended IP ACL
[
sn
]
permit protocol
source
source-wildcard
destination
destination-wildcard
[
precedence
precedence
] [
tos
tos
] [
fragment
] [
range
lower
upper
] [
time-range
time-range-name
] [
log
]
Extended IP ACLs of some important protocols:
Internet Control Message Protocol (ICMP)
[
sn
]
permit icmp
{
source source-wildcard
|
host
source
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} [
icmp-type
] [ [
icmp-type
[
icmp-code
] ] | [
icmp-message
] ] [
precedence
precedence
] [
tos
tos
] [
fragment
] [
time-range
time-range-name
]
Transmission Control Protocol (TCP)
[
sn
]
permit tcp
{
source source-wildcard
|
host
source
|
any
} [
operator
port
[
port
] ] {
destination
destination-wildcard
|
host
destination
|
any
} [
operator
port
[
port
] ] [
precedence
precedence
]
[
tos
tos
] [
fragment
] [
range
lower
upper
] [
time-range
time-range-name
] [
match-all
tcp-flag |
established
]
User Datagram Protocol (UDP)
[
sn
]
permit udp
{
source
source -wildcard
|
host
source
|
any
} [
operator
port
[
port
]] {
destination
destination-wildcard
|
host
destination
|
any
} [
operator
port
[
port
]] [
precedence
precedence
] [
tos
tos
] [
fragment
] [
range
lower
upper
] [
time-range
time-range-name
]
11. Extended MAC ACL
[
sn
]
permit
{
any
|
host
source-mac-address | source-mac-address mask
} {
any
|
host
destination-mac-address | destination -mac-address mask
} [
ethernet-type
] [
cos
[
out
] [
inner
in
] ]
12. Extended expert ACL
[
sn
]
permit
[
protocol
| [
ethernet-type
][
cos
[
out
] [
inner
in
]]] [
VID
[
out][
inner
in]
] {
source
source-wildcard
|
host
source
|
any
} {
host
source-
mac
-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} [
precedence
precedence
] [
tos
tos
][
fragment
] [
range
lower
upper
] [
time-range
time-range-name
]
When you select the Ethernet-type field or cos field:
[
sn
]
permit
{
ethernet-type|
cos
[
out
] [
inner
in
]} [
VID
[
out
][
inner
in
]] {
source
source-wildcard
|
host
source
|
any
} {
host
source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} [
time-range
time-range-name
]
When you select the protocol field:
[
sn
]
permit protocol
[
VID
[
out][
inner
in
]] {
source
source-wildcard
|
host
Source
|
any
} {
host
source-mac-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} [
precedence
precedence
] [
tos
tos
] [
fragment
] [
range
lower
upper
]
[
time-range
time-range-name
]
Extended expert ACLs of some important protocols:
Internet Control Message Protocol (ICMP)
Содержание RG-S29 Series
Страница 1: ...RG S29 Series Switch RGOS Command Reference Release 11 4 1 B12...
Страница 10: ...Command Reference Command Line Interface Commands Platform Description N A...
Страница 93: ...Command Reference Line Commands Description...
Страница 236: ...Command Reference PoE Management Commands Related Commands Command Description N A N A Platform Description N A...
Страница 248: ...Command Reference PKG_MGMT Commands...
Страница 332: ...Command Reference Protocol VLAN Commands Commands N A N A Platform Description...
Страница 350: ...Command Reference Voice VLAN Commands Description...
Страница 430: ...Command Reference LLDP Commands Description...
Страница 467: ...Command Reference ERPS Commands Commands N A N A Platform Description N A...
Страница 541: ...Command Reference IPv6 Commands Platform Description N A...
Страница 858: ...Command Reference NSM Commands Description N A N A Defaults N A Command Mode Privileged EXEC mode Usage guideline N A...
Страница 914: ...Multicast Commands 1 IPv4 Multicast Routing Commands 2 IGMP Snooping Commands...
Страница 1092: ...Configuration Guide SCC Commands Platforms N A...
Страница 1196: ...Configuration Guide IPv6 Source Guard Commands Platform Description N A...
Страница 1290: ...ACL QoS Configuration Commands 1 ACL Commands 2 QoS Commands...