Command Line Interface
4-200
4
The commands in this section configure ACLs based on IP addresses, TCP/UDP
port number, protocol type, and TCP control code. To configure IP ACLs, first create
an access list containing the required permit or deny rules, and then bind the access
list to one or more ports.
This command restricts access lists to only extended rules, or permits both standard
and extended rules. Use the
no
form to restore the default setting.
Syntax
access-list rule-mode
{
extended | mixed
}
[
no
]
access-list rule-mode
•
extended
– The system only permits extended rules, each of which
occupies the space of two standard rules.
•
mixed
– The system permits both standard and extended rules.
Default Setting
Extended mode
Command Mode
Global Configuration
Command Usage
When the rule mode is set to mixed, the following features are not supported:
• When the rule mode is changed, the change must be saved in the startup
configuration file, and the switch rebooted for the new mode to take effect.
• When using extended rule mode, each rule used in an ACL occupies the
space of two standard rules.
Table 4-50 IPv4 ACL Commands
Command
Function
Mode
Page
access-list rule-mode
Permits only extended rules, or permits both standard and
extended rules
GC
4-200
access-list ip
Creates an IPv4 ACL and enters configuration mode for
standard or extended IPv4 ACLs
GC
4-201
permit, deny
Filters packets matching a specified source IPv4 address
STD-ACL
4-202
permit, deny
Filters packets meeting the specified criteria, including
source and destination IPv4 address, TCP/UDP port
number, protocol type, and TCP control code
EXT-ACL
4-203
show ip access-list
Displays the rules for configured IPv4 ACLs
PE
4-205
ip access-group
Adds a port to an IPv4 ACL
IC
4-205
show ip access-group
Shows port assignments for IPv4 ACLs
PE
4-205
Содержание 6152PL2 FICHE
Страница 2: ......
Страница 6: ...vi ...
Страница 8: ...viii ...
Страница 32: ...Tables xxxii ...
Страница 38: ...Figures xxxviii ...
Страница 56: ...Initial Configuration 2 10 2 ...
Страница 378: ...Configuring the Switch 3 322 3 ...
Страница 651: ...Address Table Commands 4 273 4 Example Console show mac address table aging time Aging time 100 sec Console ...
Страница 817: ......
Страница 818: ...SMC6128PL2 SMC6152PL2 149100000007A R01 ...