Defaults
All access lists contain an implicit “deny any”; that is, if no match occurs, the packet is
dropped.
Command Modes
CONFIGURATION
Command History
Version 8.3.11.1
Introduced on the Z9000.
Version 8.3.10.0
Introduced on the S4810.
Version 8.1.1.0
Introduced on the E-Series ExaScale.
Version 7.8.1.0
Increased the name string to accept up to 140 characters. Prior to
7.8.1.0, names were up to 16 characters long.
Version 7.6.1.0
Introduced on the S-Series.
Version 7.5.1.0
Introduced on the C-Series.
pre-Version
6.2.1.1
Introduced on the E-Series.
Usage
Information
The number of entries allowed per ACL is hardware-dependent. For detailed specification on
entries allowed per ACL, refer to your line card documentation.
Prior to 7.8.1.0, names are up to 16 characters long.
Example
FTOS(conf)#ip access-list extended TESTListEXTEND
FTOS(config-ext-nacl)#
Related
Commands
ip access-list standard
– configures a standard IP access list.
show config
– displays the current configuration.
permit
Configure a filter to pass IP packets meeting the filter criteria.
C-Series, E-Series, S-Series, Z-Series, S4810
Syntax
permit {ip |
ip-protocol-number
} {
source mask
| any | host
ip-
address
} {
destination mask
| any | host
ip-address
} [count
[byte] | log] [dscp
value
] [order] [monitor] [fragments]
To remove this filter, you have two choices:
•
Use the
no seq
sequence-number
command if you know the filter’s sequence
number.
•
Use the
no deny {ip |
ip-protocol-number
} {
source mask
| any
| host
ip-address
} {
destination mask
| any | host
ip-
address
}
command.
Parameters
ip
Enter the keyword
ip
to configure a generic IP access list. The
keyword
ip
specifies that the access list will permit all IP protocols.
ip-protocol-
number
Enter a number from 0 to 255 to permit based on the protocol
identified in the IP protocol header. The S4810 range is 0 to 128.
241
Summary of Contents for Force10 Z9000
Page 1: ...FTOS Command Line Reference Guide for the Z9000 System FTOS 9 1 0 0 ...
Page 96: ...96 ...
Page 194: ...194 ...
Page 312: ...312 ...
Page 540: ...540 ...
Page 546: ...546 ...
Page 560: ...560 ...
Page 566: ...566 ...
Page 590: ...action act UpdateCounter param0 1 0x01 param1 0 0x00 output truncated 590 ...
Page 624: ...624 ...
Page 638: ...638 ...
Page 648: ...648 ...
Page 659: ...Related Commands show gvrp displays the GVRP configuration 659 ...
Page 660: ...660 ...
Page 834: ...834 ...
Page 854: ...854 ...
Page 906: ...906 ...
Page 914: ...914 ...
Page 976: ...976 ...
Page 990: ...990 ...
Page 1006: ...1006 ...
Page 1008: ...1008 ...
Page 1026: ...1026 ...
Page 1145: ...10 211 1 2 Outgoing interface list GigabitEthernet 8 0 1145 ...
Page 1146: ...1146 ...
Page 1156: ...1156 ...
Page 1166: ...1166 ...
Page 1180: ...1180 ...
Page 1258: ...1258 ...
Page 1272: ...1272 ...
Page 1394: ...1394 ...
Page 1400: ...1400 ...
Page 1410: ...1410 ...
Page 1424: ...1424 ...
Page 1444: ...1444 ...
Page 1468: ...Version 8 3 8 0 Introduced on the S4810 1468 ...
Page 1470: ...1470 ...