Result
The IP access control list for ICMP messages has been configured.
Note
Subnet mask for individual hosts
If you create the rule for a single system (one IPv4 address), specify the subnet mask
"255.255.255.255". As an alternative, you can specify the keyword "host" followed by the IPv4
address.
Further notes
You delete an IP access control list with the
no ip access-list standard <acl-
num>
command.
You display the configuration of the access control list with the
show access-lists
command.
11.5.5.4
deny icmp
Description
With this command, you configure an IP access control list for ICMP frames.
You have the following options:
● All incoming and/or outgoing ICMP messages are not forwarded.
● Incoming and/or outgoing ICMP messages of a specific host are not forwarded.
● Incoming and/or outgoing ICMP messages of hosts of a specific subnet are not forwarded.
Note
Processing order of the lists
The access control lists are processed on the interface in the order in which they were created.
The index number of the access control list is not used for this.
Requirement
You are in the ACL standard configuration mode.
The command prompt is as follows:
cli(config-std-nacl)#
Security and authentication
11.5 IP access control list
SCALANCE W770/W730 acc. to IEEE 802.11n Command Line Interface
Configuration Manual, 09/2017, C79000-G8976-C324-08
567