Release :
1.0
878 / 913
34 ACL (Access Control Lists)
ACLs (Access Control Lists) filter network traffic by controlling whether routed packets are forwarded or
blocked at the router's interfaces. ACLs are used to block IP packets from being forwarded by a router.
The router examines each packet to determine whether to forward or drop the packet, based on the
criteria specified within the access lists. Access list criteria can be the source address of the traffic, the
destination address of the traffic, the upper-layer protocol or other information.
There are many reasons to configure access lists - access lists can be used to restrict contents of routing
updates or to provide traffic flow control. But one of the most important reasons to configure access lists
is to provide security for the network.
Access lists must be used to provide a basic level of security for accessing the network. If access lists has
not been configured on the router, all packets passing through the router can be allowed onto all parts of
the network.
For example, access lists can allow one host to access a part of the network and prevent another host
from accessing the same area.
The list of CLI commands for the configuration of ACL is as follows:
ip access-list
mac access-list extended
permit - standard mode
deny - standard mode
permit- ip/ospf/pim/protocol type
deny - ip/ospf/pim/protocol type
permit tcp
deny tcp
permit udp
deny udp
permit icmp
deny icmp
Содержание Intelligent Switch
Страница 1: ...Release 1 0 1 913 Super Micro Intelligent Switch User Guide Release 1 0 Document SMIS_CLI_GUIDE 001 ...
Страница 19: ...Release 1 0 19 913 34 17 show access lists 911 ...
Страница 82: ...Release 1 0 82 913 3 44 clear screen This command clears the screen clear screen Mode All Modes ...
Страница 102: ...Release 1 0 102 913 3 64 reload This command restarts the switch reload Mode Privileged EXEC Mode Example smis reload ...
Страница 154: ...Release 1 0 154 913 ...
Страница 208: ...Release 1 0 208 913 dot1x auth mode ...
Страница 247: ...Release 1 0 247 913 ...
Страница 252: ...Release 1 0 252 913 show etherchannel Displays etherchannel load balance information ...
Страница 296: ...Release 1 0 296 913 Gi0 10 Related Command ip igmp snooping Enables IGMP snooping in the switch a specific VLAN ...
Страница 311: ...Release 1 0 311 913 ...
Страница 344: ...Release 1 0 344 913 ...
Страница 346: ...Release 1 0 346 913 show debugging Displays state of each debugging option ...
Страница 369: ...Release 1 0 369 913 Related Command clear vlan statistics Clears the VLAN counters ...
Страница 372: ...Release 1 0 372 913 ...
Страница 403: ...Release 1 0 403 913 ...
Страница 430: ...Release 1 0 430 913 ...
Страница 620: ...Release 1 0 620 913 show ip ospf database summary show ip ospf database ...
Страница 630: ...Release 1 0 630 913 area translation role Configures the translation role for the NSSA ...
Страница 642: ...Release 1 0 642 913 ...
Страница 699: ...Release 1 0 699 913 ...
Страница 764: ...Release 1 0 764 913 ...
Страница 777: ...Release 1 0 777 913 0 UDPDgrams ...
Страница 800: ...Release 1 0 800 913 show ipv6 ospf route show ipv6 ospf areas show ipv6 ospf host show ipv6 ospf redist config ...
Страница 821: ...Release 1 0 821 913 ...
Страница 852: ...Release 1 0 852 913 no area Deletes an area ...
Страница 862: ...Release 1 0 862 913 show cosq algorithm show cosq weights bw ...
Страница 879: ...Release 1 0 879 913 ip access group mac access group permit deny show access lists ...
Страница 907: ...Release 1 0 907 913 ...
Страница 910: ...Release 1 0 910 913 ...