Security and authentication
11.4 IP access control list
SCALANCE XM-400/XR-500 Command Line Interface (CLI)
Configuration Manual, 06/2016, C79000-G8976-C252-11
841
Parameter
Description
Range of values / note
dscp
Keyword for the Differentiated Services
Codepoint
-
value
Value for the Differentiated Services
Codepoint
0 ... 63
For information on names of addresses and interfaces, refer to the section "Interface
identifiers and addresses (Page 42)".
Result
The IP access list has been configured.
Note
Subnet mask for individual hosts
If you create the rule for a single system (one IP address), you will need to specify the
subnet mask "255,255,255,255". As an alternative, you can specify the keyword "host"
followed by the IP address.
Further notes
You delete an IP access control list with the
no ip access-list standard <acl-num>
command.
You display the configuration of the access control list with the
show access-lists
command.
11.4.4.2
deny
Description
With this command, you configure an IP access control list. The IP ACL contains a
description of the IP addresses for which the incoming and outgoing frames will not be
forwarded.
You have the following options:
●
All incoming and/or outgoing frames are not forwarded.
●
Incoming and/or outgoing frames of a specific host are not forwarded.
●
Incoming and/or outgoing frames of hosts of a specific subnet are not forwarded.
●
Incoming and/or outgoing frames of a specific protocol are not forwarded.