Chapter 10
| Access Control Lists
IPv4 ACLs
– 319 –
permit, deny
(Standard IP ACL)
This command adds a rule to a Standard IPv4 ACL. The rule sets a filter
condition for packets emanating from the specified source. Use the
no
form to
remove a rule.
Syntax
{
permit
|
deny
} {
any
|
source bitmask |
host
source
}
[
time-range
time-range-name
]
no
{
permit
|
deny
} {
any
|
source bitmask |
host
source
}
any
– Any source IP address.
source
– Source IP address.
bitmask
– Dotted decimal number representing the address bits to
match.
host
– Keyword followed by a specific IP address.
time-range-name
- Name of the time range. (Range: 1-16
characters)
Default Setting
None
Command Mode
Standard IPv4 ACL
Command Usage
◆
New rules are appended to the end of the list.
◆
Address bit masks are similar to a subnet mask, containing four integers
from 0 to 255, each separated by a period. The binary mask uses 1 bits to
indicate “match” and 0 bits to indicate “ignore.” The bitmask is bitwise
ANDed with the specified source IP address, and then compared with the
address for each IP packet entering the port(s) to which this ACL has been
assigned.
Example
This example configures one permit rule for the specific address 10.1.1.21
and another rule for the address range 168.92.16.x – 168.92.31.x using a
bitmask.
Console(config-std-acl)#permit host 10.1.1.21
Console(config-std-acl)#permit 168.92.16.0 255.255.240.0
Console(config-std-acl)#
Related Commands
Содержание SC30010
Страница 1: ...C 300 Series Gigabit Managed Switch CLI Reference Guide SOFTWARE RELEASE V1 1 10 171 www signamax com ...
Страница 2: ...CLI Reference Guide SC30010 C 300 48 Port Gigabit Managed Switch E122017 KS R01 ...
Страница 482: ...Chapter 19 Class of Service Commands Priority Commands Layer 3 and 4 482 ...
Страница 670: ......
Страница 671: ...E122017 KS R01 ...