Access Control Lists
7-2
7
-
IP Extended
: IPv4 ACL mode that filters packets based on source or
destination IPv4 address, as well as protocol type and protocol port number.
If the “TCP” protocol is specified, then you can also filter packets based on the
TCP control code.
-
IPv6 Standard
: IPv6 ACL mode that filters packets based on the source IPv6
address.
-
IPv6 Extended
: IPv6 ACL mode that filters packets based on the destination IP
address, as well as the type of the next header and the flow label (i.e., a request
for special handling by IPv6 routers).
-
MAC
: MAC ACL mode that filters packets based on the source or destination
MAC address and the Ethernet frame type (RFC 1060).
Web
– Click Security, ACL, Configuration. Enter an ACL name in the Name field,
select the list type (IP Standard, IP Extended, MAC, IPv6 Standard, IPv6 Extended),
and click Add to open the configuration page for the new list.
Figure 7-1 Selecting ACL Type
CLI
– This example creates a standard IP ACL named bill.
Configuring a Standard IPv4 ACL
Command Attributes
•
Action
– An ACL can contain any combination of permit or deny rules.
•
Address Type
– Specifies the source IP address. Use “Any” to include all possible
addresses, “Host” to specify a specific host address in the Address field, or “IP” to
specify a range of addresses with the Address and SubMask fields. (Options: Any,
Host, IP; Default: Any)
•
IP Address
– Source IP address.
•
Subnet Mask
– A subnet mask containing four integers from 0 to 255, each
separated by a period. The mask uses 1 bits to indicate “match” and 0 bits to
indicate “ignore.” The mask is bitwise ANDed with the specified source IP address,
and compared with the address for each IP packet entering the port(s) to which this
ACL has been assigned.
Console(config)#access-list ip standard bill
26-2
Console(config-std-acl)#
Содержание 8926EM
Страница 6: ...ii ...
Страница 34: ...Getting Started ...
Страница 44: ...Introduction 1 10 1 ...
Страница 62: ...Initial Configuration 2 18 2 ...
Страница 64: ...Switch Management ...
Страница 76: ...Configuring the Switch 3 12 3 ...
Страница 118: ...Basic Management Tasks 4 42 4 ...
Страница 164: ...User Authentication 6 28 6 ...
Страница 176: ...Access Control Lists 7 12 7 ...
Страница 284: ...Quality of Service 14 8 14 ...
Страница 294: ...Multicast Filtering 15 10 15 ...
Страница 300: ...Domain Name Service 16 6 16 ...
Страница 310: ...Dynamic Host Configuration Protocol 17 10 17 ...
Страница 320: ...Configuring Router Redundancy 18 10 18 ...
Страница 344: ...IP Routing 19 24 19 ...
Страница 356: ...Unicast Routing 20 12 20 Web Click Routing Protocol RIP Statistics Figure 20 5 RIP Statistics ...
Страница 386: ...Unicast Routing 20 42 20 ...
Страница 388: ...Command Line Interface ...
Страница 400: ...Overview of the Command Line Interface 21 12 21 ...
Страница 466: ...SNMP Commands 24 16 24 ...
Страница 520: ...Access Control List Commands 26 18 26 ...
Страница 546: ...Rate Limit Commands 30 2 30 ...
Страница 612: ...VLAN Commands 34 24 34 ...
Страница 626: ...Class of Service Commands 35 14 35 ...
Страница 670: ...DHCP Commands 39 16 39 ...
Страница 716: ...IP Interface Commands 41 36 41 ...
Страница 768: ...IP Routing Commands 42 52 42 ...
Страница 770: ...Appendices ...
Страница 791: ......
Страница 792: ...20 Mason Irvine CA 92618 Phn 949 679 8000 www smc com 150200062800A R02 149100000035A R01 SMC8926EM SMC8950EM ...