206
ACL Commands
access-list
Use the
access-list
command in Global Configuration mode to create an
Access Control List (ACL) that is identified by the parameter
list-name
.
Syntax
access-list
std-list-num
{
deny
|
permit
} {
srcip
srcmask
|
every
} [
log
]
[
assign-queue
queue-id
] [
redirect
interface
|
mirror
interface
]
access-list
ext-list-num
{
deny
|
permit
} {
every
| {[
icmp
|
igmp
|
ip
|
tcp
|
udp
|
number
] {
srcip
srcmask
|
any
} [
eq
[
portkey
|
portvalue
]] {
dstip
dstmask
|
any
} [
eq
[
portkey
|
portvalue
]] [
precedence
precedence
|
tos
tos
tosmask
|
dscp
dscp
] [log] [
assign-queue
queue-id
] [
redirect
interface
|
mirror
interface
]}}
no access-list
list-name
•
list-name
— Access-list name up to 31 characters in length.
•
deny | permit
— Specifies whether the IP ACL rule permits or denies an
action.
•
every
— Allows all protocols.
•
eq
— Equal. Refers to the Layer 4 port number being used as match
criteria. The first reference is source match criteria, the second is
destination match criteria.
•
number
— Standard protocol number. Protocol keywords
icmp,igmp,ip,tcp,udp.
•
srcip
— Source IP address.
•
srcmask
— Source IP mask.
•
dstip
— Destination IP address.
•
dstmask
— Destination IP mask.
•
portvalue
— The source layer 4 port match condition for the ACL rule is
specified by the port value parameter (Range: 0–65535).
•
portkey
— Or you can specify the
portkey
, which can be one of the
following keywords: domain, echo, ftp, ftpdata, http, smtp, snmp, telnet,
tftp, and www.
• log — Specifies that this rule is to be logged.
Summary of Contents for PowerConnect 6224
Page 54: ...54 Contents show ip https 1369 state 1370 ...
Page 134: ...134 Command Groups ...
Page 186: ...186 Using the CLI ...
Page 216: ...216 ACL Commands ...
Page 236: ...236 Address Table Commands ...
Page 250: ...250 CDP Interoperability Commands ...
Page 256: ...256 DHCP Layer 2 Relay Commands Example console config dhcp l2relay vlan 10 340 345 ...
Page 284: ...284 Dynamic ARP Inspection Commands ...
Page 318: ...318 Ethernet Configuration Commands ...
Page 330: ...330 GVRP Commands ...
Page 344: ...344 IGMP Snooping Commands ...
Page 368: ...368 IP Addressing Commands ...
Page 378: ...378 IPv6 Access List Commands ...
Page 386: ...386 IPv6 MLD Snooping Querier Commands MLD Version Indicates the version of MLD ...
Page 393: ...LACP Commands 393 Oper Key 29 Partner System Priority 0 MAC Address 000000 000000 Oper Key 14 ...
Page 394: ...394 LACP Commands ...
Page 404: ...404 Link Dependency Commands ...
Page 432: ...432 LLDP Commands ...
Page 446: ...446 Port Monitor Commands 1 Enable 1 g10 1 g8 Rx Tx ...
Page 572: ...572 TACACS Commands ...
Page 610: ...610 VLAN Commands ...
Page 616: ...616 Voice VLAN Commands ...
Page 618: ...618 802 1x Commands 802 1x Option 81 radius server attribute 4 ...
Page 656: ...656 ARP Commands IP Address MAC Address Interface Type Age console ...
Page 822: ...822 IPv6 Routing Commands ...
Page 826: ...826 Loopback Interface Commands ...
Page 828: ...828 Multicast Commands show ip pimsm rphash show ip pimsm rp mapping ...
Page 854: ...854 Multicast Commands ...
Page 930: ...930 OSPF Commands ...
Page 933: ...OSPFv3 Commands 933 show ipv6 ospf virtual link show ipv6 ospf virtual link brief ...
Page 1004: ...1004 PIM SM Commands ...
Page 1014: ...1014 Router Discovery Protocol Commands ...
Page 1054: ...1054 Autoconfig Commands boot host dhcp boot host retry count show boot ...
Page 1058: ...1058 Autoconfig Commands ...
Page 1094: ...1094 Captive Portal Commands ...
Page 1110: ...1110 Clock Commands ...
Page 1130: ...1130 Configuration and Image File Commands ...
Page 1142: ...1142 Denial of Service Commands ...
Page 1178: ...1178 Power Over Ethernet Commands ...
Page 1220: ...1220 Serviceability Tracing Packet Commands ...
Page 1232: ...1232 Sflow Commands ...
Page 1262: ...1262 SNMP Commands ...
Page 1346: ...1346 System Management Commands 4 5 ...
Page 1350: ...1350 Telnet Server Commands ...
Page 1372: ...1372 Web Server Commands ...