Chapter 25: Access Control Lists
MAC ACLs
– 912 –
no
{
permit
|
deny
}
{
any
|
host source
|
source address-bitmask
}
{
any
|
host destination
|
destination address-bitmask
}
[
cos
cos
cos-bitmask
] [
vid
vid vid-bitmask
]
[
ethertype
protocol
[
protocol
-
bitmask
]]
{{
ip
{
any
|
host source-ip
|
source-ip network-mask
}
{
any
|
host destination-ip
|
destination-ip network-mask
}
{
ipv6
{
any
|
host source-ipv6
|
source-ipv6/prefix-length
}
{
any
|
host destination-ipv6
|
destination-ipv6/prefix-length
}}
[
protocol
protocol
]
[
l4-source-port
sport
[
port-bitmask
]]
[
l4-destination-port
dport
[
port-bitmask
]}]
N
OTE
:
The default is for Ethernet II packets.
{
permit
|
deny
}
tagged-eth2
{
any
|
host source
|
source address-bitmask
}
{
any
|
host destination
|
destination address-bitmask
}
[
cos
cos
cos-bitmask
] [
vid
vid vid-bitmask
]
[
ethertype
ethertype
[
ethertype
-
bitmask
]] {{
ip
{
any
|
host source-ip
|
source-ip network-mask
}
{
any
|
host destination-ip
|
destination-ip network-mask
}
{
ipv6
{
any
|
host source-ipv6
|
source-ipv6/prefix-length
}
{
any
|
host destination-ipv6
|
destination-ipv6/prefix-length
}}
[
protocol
protocol
]
[
l4-source-port
sport
[
port-bitmask
]]
[
l4-destination-port
dport
[
port-bitmask
]}]
[
time-range
time-range-name
]
no
{
permit
|
deny
}
tagged-eth2
{
any
|
host source
|
source address-bitmask
}
{
any
|
host destination
|
destination address-bitmask
}
[
cos
cos
cos-bitmask
] [
vid
vid vid-bitmask
]
[
ethertype
ethertype
[
ethertype
-
bitmask
]]
{{
ip
{
any
|
host source-ip
|
source-ip network-mask
}
{
any
|
host destination-ip
|
destination-ip network-mask
}
{
ipv6
{
any
|
host source-ipv6
|
source-ipv6/prefix-length
}
{
any
|
host destination-ipv6
|
destination-ipv6/prefix-length
}}
[
protocol
protocol
]
[
l4-source-port
sport
[
port-bitmask
]]
[
l4-destination-port
dport
[
port-bitmask
]}]
{
permit
|
deny
}
untagged-eth2
{
any
|
host source
|
source address-bitmask
}
{
any
|
host destination
|
destination address-bitmask
}
[
ethertype
ethertype
[
ethertype
-
bitmask
]]
{{
ip
{
any
|
host source-ip
|
source-ip network-mask
}
{
any
|
host destination-ip
|
destination-ip network-mask
}
{
ipv6
{
any
|
host source-ipv6
|
source-ipv6/prefix-length
}
{
any
|
host destination-ipv6
|
destination-ipv6/prefix-length
}}
[
protocol
protocol
]
[
l4-source-port
sport
[
port-bitmask
]]
[
l4-destination-port
dport
[
port-bitmask
]}]
[
time-range
time-range-name
]
Содержание SSE-G2252
Страница 42: ...44 General IP Routing on page 627...
Страница 174: ...Chapter 6 VLAN Configuration Configuring VLAN Mirroring 178 Figure 6 27 Showing the VLANs to Mirror...
Страница 511: ...Chapter 14 Basic Administration Protocols UDLD Configuration 518 Figure 14 100 Displaying UDLD Neighbor Information...
Страница 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Страница 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Страница 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Страница 1007: ...Chapter 33 Address Table Commands 1019...
Страница 1137: ...Chapter 38 Quality of Service Commands 1150...
Страница 1366: ...Chapter 46 IP Routing Commands Global Routing Configuration 1381 Connected 2 Total 2 FIB 0 Console...