18.10.2013 Views

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Parameters<br />

Defaults Not configured.<br />

permit tcp<br />

source Enter <strong>the</strong> IP address of <strong>the</strong> network or host from which <strong>the</strong> packets were sent.<br />

mask Enter a network mask in /prefix <strong>for</strong>mat (/x) or A.B.C.D. The mask, when<br />

specified in A.B.C.D <strong>for</strong>mat, may be ei<strong>the</strong>r contiguous or non-contiguous.<br />

any Enter <strong>the</strong> keyword any to specify that all routes are subject to <strong>the</strong> filter.<br />

host ip-address Enter <strong>the</strong> keyword host followed by <strong>the</strong> IP address to specify a host IP<br />

address.<br />

bit Enter a flag or combination of bits:<br />

ack: acknowledgement field<br />

fin: finish (no more data from <strong>the</strong> user)<br />

psh: push function<br />

rst: reset <strong>the</strong> connection<br />

syn: synchronize sequence numbers<br />

urg: urgent field<br />

operator (OPTIONAL) Enter one of <strong>the</strong> following logical operand:<br />

• eq = equal to<br />

• neq = not equal to<br />

• gt = greater than<br />

• lt = less than<br />

• range = inclusive range of ports (you must specify two port <strong>for</strong> <strong>the</strong> port<br />

parameter.)<br />

port port Enter <strong>the</strong> application layer port number. Enter two port numbers if using <strong>the</strong><br />

range logical operand.<br />

Range: 0 to 65535.<br />

The following list includes some common TCP port numbers:<br />

23 = Telnet<br />

20 and 21 = FTP<br />

25 = SMTP<br />

169 = SNMP<br />

destination Enter <strong>the</strong> IP address of <strong>the</strong> network or host to which <strong>the</strong> packets are sent.<br />

mask Enter a network mask in /prefix <strong>for</strong>mat (/x) or A.B.C.D. The mask, when<br />

specified in A.B.C.D <strong>for</strong>mat, may be ei<strong>the</strong>r contiguous or non-contiguous.<br />

count (OPTIONAL) Enter <strong>the</strong> keyword count to count packets processed by <strong>the</strong><br />

filter.<br />

byte (OPTIONAL) Enter <strong>the</strong> keyword byte to count bytes processed by <strong>the</strong> filter.<br />

log (OPTIONAL) Enter <strong>the</strong> keyword log to enter ACL matches in <strong>the</strong> log.<br />

order (OPTIONAL) Enter <strong>the</strong> keyword order to specify <strong>the</strong> QoS order of priority <strong>for</strong><br />

<strong>the</strong> ACL entry.<br />

Range: 0-254 (where 0 is <strong>the</strong> highest priority and 254 is <strong>the</strong> lowest; lower<br />

order numbers have a higher priority)<br />

Default: If <strong>the</strong> order option is not configure, by default ACLs will have <strong>the</strong><br />

lowest default order (255).<br />

monitor (OPTIONAL) Enter <strong>the</strong> keyword monitor to monitor traffic on <strong>the</strong> monitoring<br />

interface specified in <strong>the</strong> flow-based monitoring session along with <strong>the</strong> filter<br />

operation.<br />

<strong>FTOS</strong> <strong>Command</strong> Line Interface <strong>Reference</strong>, version 7.6.1.0 335

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!