ProCurve 6200yl User's Guide Page 294

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 293
10-8
Access Control Lists (ACLs)
Overview of Options for Applying ACLs on the Switch
Table 10-2. Command Summary for Extended ACLs
Action Command(s) Page
Create an Extended,
Named ACL
or
Add an ACE to the End
of an Existing,
Extended ACL
ProCurve(config)# ip access-list extended < name-str | 100-199 >
ProCurve(config-std-nacl)# < deny | permit >
< ip | ip-protocol | ip-protocol-nbr >
< any | host <SA > | SSA/< mask-length > | SA < mask >>
1
< any | host < DA > | DA/< mask-length > | DA < mask >>
1
< tcp | udp >
< any | host <SA > | SA/< mask-length > | SA < mask >>
1
[comparison-operator < value >]
< any | host <DA > | DA/< mask-length > | DA < mask >>
1
[comparison-operator < value >]
[established]
< igmp >
< any | host <SA > | SA/< mask-length > | SA < mask >>
1
< any | host < DA > | DA/< mask-length > | DA < mask >>
1
[ igmp-packet-type ]
< icmp >
< any | host <SA > | SA/< mask-length > | SA < mask >>
1
< any | host < DA > | DA/< mask-length > | DA < mask >>
1
[ [< 0 - 255 > [ 0 - 255 ] ] | icmp-message ]
[precedence < priority >]
[tos < tos- setting >]
[log]
2
10-62
Create an Extended,
Numbered ACL
or
Add an ACE to the End
of an Existing,
Numbered ACL
ProCurve(config)# access-list < 100-199 > < deny | permit >
< ip-options |tcp/udp-options |igmp-options |icmp-options >
[precedence < priority >]
[tos < tos- setting >]
[log]
2
Note: Uses the same IP, TCP/UDP, IGMP, and ICMP options as shown above for
“Create an Extended, Named ACL”.
10-74
Insert an ACE by
Assigning a Sequence
Number
ProCurve(config)# ip access-list extended < name-str | 100-199 >
ProCurve(config-ext-nacl)# 1-2147483647 < deny | permit >
Uses the options shown above for “Create an Extended, Named ACL”.
10-88
Delete an ACE by
Specifying Its
Sequence Number
ProCurve(config)# ip access-list extended < name-str | 100-199 >
ProCurve(config-std-nacl)# no < 1-2147483647 >
10-90
Resequence the ACEs
in an ACL
ProCurve(config)# ip access-list resequence < name-str | 100-199 >
< 1-2147483647 > < 1-2147483646 >
10-91
1
The mask can be in either dotted-decimal notation (such as 0.0.15.255) or CIDR notation (such as /20).
2
The [ log ] function applies only to “deny” ACLs, and generates a message only when there is a “deny” match.
Page view 293
1 2 ... 289 290 291 292 293 294 295 296 297 298 299 ... 595 596

Comments to this Manuals

No comments