30.06.2015 Views

8.28 MB - Edge-Core

8.28 MB - Edge-Core

8.28 MB - Edge-Core

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Access Control List Commands<br />

4<br />

permit, deny (Extended ACL)<br />

This command adds a rule to an Extended IP ACL. The rule sets a filter condition for<br />

packets with specific source or destination IP addresses, protocol types, source or<br />

destination protocol ports, or TCP control codes. Use the no form to remove a rule.<br />

Syntax<br />

[no] {permit | deny} [protocol-number | udp]<br />

{any | source address-bitmask | host source}<br />

{any | destination address-bitmask | host destination}<br />

[precedence precedence] [tos tos] [dscp dscp]<br />

[source-port sport [end]] [destination-port dport [end]]<br />

[no] {permit | deny} tcp<br />

{any | source address-bitmask | host source}<br />

{any | destination address-bitmask | host destination}<br />

[precedence precedence] [tos tos] [dscp dscp]<br />

[source-port sport [end]] [destination-port dport [end]]<br />

[control-flag control-flags flag-bitmask]<br />

• protocol-number – A specific protocol number. (Range: 0-255)<br />

• source – Source IP address.<br />

• destination – Destination IP address.<br />

• address-bitmask – Decimal number representing the address bits to match.<br />

• host – Keyword followed by a specific IP address.<br />

• precedence – IP precedence level. (Range: 0-7)<br />

• tos – Type of Service level. (Range: 0-15)<br />

• dscp – DSCP priority level. (Range: 0-63)<br />

• sport – Protocol 17 source port number. (Range: 0-65535)<br />

• dport – Protocol 1 destination port number. (Range: 0-65535)<br />

• end – Upper bound of the protocol port range. (Range: 0-65535)<br />

• control-flags – Decimal number (representing a bit string) that specifies flag<br />

bits in byte 14 of the TCP header. (Range: 0-63)<br />

• flag-bitmask – Decimal number representing the code bits to match.<br />

(Range: 0-63)<br />

Default Setting<br />

None<br />

Command Mode<br />

Extended ACL<br />

17. Includes TCP, UDP or other Protocol types.<br />

4-89

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!