3.1.2.1 LIST ALL
Displays all the Access Control List configuration entries (i.e. the whole configuration). The configured entries are
presented together with those that are in the cache. This command should be followed by other commands that spe-
cify the information to be displayed in further detail. Stateful Access Lists cannot be listed and, therefore, do not ap-
pear when executing this command.
Syntax:
Access Lists>list all ?
all-access-lists
Displays information for all active access lists
address-filter-access-lists
Displays information for access lists that
match an address search pattern
access-list
Displays information for a specified access list
3.1.2.1.1 LIST ALL ALL-ACCESS-LISTS
Displays all the Access Control Lists for the active configuration. Configured entries and those in the cache are both
presented.
Example:
Access Lists>list all all-access-lists
Standard Access List 1, assigned to no protocol
ACCESS LIST ENTRIES
3
PERMIT
SRC=234.233.44.33/32
Hits: 0
1
DENY
SRC=192.23.0.22/255.255.0.255
Hits: 0
Extended Access List 100, assigned to no protocol
ACCESS LIST CACHE. Hits = 0, Miss = 0
Cache size: 32 entries, Promotion zone: 6 entries
ACCESS LIST ENTRIES
1
PERMIT
SRC=172.25.54.33/32
DES=192.34.0.0/16
Conn:0
PROT=21
Hits: 0
2
DENY
SRC=0.0.0.0/0
DES=0.0.0.0/0
Conn:0
Hits: 0
3
PERMIT
SRC=0.0.0.0/0
DES=0.0.0.0/0
Conn:33
PROT=21-44
SPORT=34-56
DPORT=2-4
Hits: 0
Extended Access List 101, assigned to IPSec
ACCESS LIST CACHE. Hits = 0, Miss = 0
Cache size: 32 entries, Promotion zone: 6 entries
ACCESS LIST ENTRIES
1
PERMIT
SRC=172.24.51.57/32
DES=172.60.1.163/32
Conn:0
Label=22
Hits: 0
2
PERMIT
SRC=0.0.0.0/0
DES=0.0.0.0/0
Conn:0
Hits: 0
Extended Access List 103, assigned to no protocol
ACCESS LIST CACHE. Hits = 0, Miss = 0
Cache size: 32 entries, Promotion zone: 6 entries
ACCESS LIST ENTRIES
1
PERMIT
SRC=1.0.0.0/8
DES=2.0.0.0/8
Conn:0
PROT=23-43
SPORT=23-45
DPORT=23-43
TOS OCTET=0
Hits: 0
Access Lists>
3.1.2.1.2 LIST ALL ADDRESS-FILTER-ACCESS-LISTS
Displays all the Access Control List entries that contain the subnet IP address and mask included in the search pat-
tern entered after the command. The available lists are also presented. The configured entries, together with those in
the cache, are also shown. If the IP address and mask entered are 0.0.0.0, all Access Lists are indexed.
Syntax:
Access Lists>list all address-filter-access-lists <IPaddress> <subnet>
bintec elmeg
3 Monitoring
Access Control
39