ProCurve 6200yl User's Guide Page 347

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 346
10-61
Access Control Lists (ACLs)
Configuring Extended ACLs
Standard ACLs use only source IP addresses for filtering criteria, extended
ACLs use multiple filtering criteria. This enables you to more closely define
your IP packet-filtering. Extended ACLs enable filtering on the following:
Source and destination IP addresses (required), in one of the
following options:
specific host IP
subnet or group of IP addresses
any IP address
choice of any IP protocol
optional packet-type criteria for IGMP, and ICMP traffic
optional source and/or destination TCP or UDP port, with a further
option for comparison operators and (for TCP) an option for estab-
lishing connections
filtering for TCP traffic based on whether the subject traffic is initi-
ating a connection (“established” option)
optional IP precedence and ToS criteria
The switch allows up to 2048 ACLs in any combination of numeric and
alphanumeric identifiers, and determines the total from the number of unique
identifiers in the configuration. For example, configuring two ACLs results in
an ACL total of two, even if neither is assigned to an interface. If you then
assign a nonexistent ACL to an interface, the new ACL total is three, because
the switch now has three unique ACL names in its configuration. (For more
on ACL limits, refer to “Monitoring Shared Resources” on page 10-114.)
Enter or Remove a
Remark
ProCurve(config)# ip access-list extended < name-str | 100-199 >
ProCurve(config-ext-nacl)# [ remark < remark-str > | no < 1 - 2147483647 > remark ]
For numbered, extended ACLs only, the following remark commands can be
substituted for the above:
ProCurve(config)# access-list < 100 - 199 > remark < remark-str >
ProCurve(config)# [no] access-list < 100 - 199 > remark
10-92
10-94
Delete an Extended
ACL
ProCurve(config)# no ip access-list extended < name-str | 100-199 >
For numbered, extended ACLs only, the following command can also be used:
ProCurve(config)# no access-list < 100 - 199 >
10-85
Action Command(s) Page
Page view 346
1 2 ... 342 343 344 345 346 347 348 349 350 351 352 ... 595 596

Comments to this Manuals

No comments