699
FILE LOCATION: C:\Users\gina\Desktop\Checkout_new\CLI Folders\Dell Contax
CLI\files\ACL.fm
D E L L C O N F ID E N T I A L – P RE L IM I N A RY 2 0 1 2 - F O R P R O O F O N LY
Syntax
deny
protocol {any | source source-wildcard} {any | destination destination-
wildcard} [dscp number | precedence number] [time-range time-range-
name] [disable-port | log-input]
deny
icmp {any | source source-wildcard} {any | destination destination-
wildcard{any|icmp-type} {any|icmp-code} [dscp number | precedence
number] [time-range time-range-name] [disable-port | log-input
]
deny
igmp {any | source source-wildcard} {any | destination destination-
wildcard}[igmp-type] [dscp number | precedence number] [time-range
time-range-name] [disable-port | log-input]
deny
tcp {any | source source-wildcard} {any|source-port/port-range}{any |
destination destination-wildcard} {any|destination-port/port-range } [dscp
number | precedence number] [match-all list-of-flags] [time-range time-
range-name] [disable-port | log-input]
deny
udp {any | source source-wildcard} {any|source-port/port-range} {any
| destination destination-wildcard} {any|destination-port/port-range } [dscp
number | precedence number] [match-all time-range-name] [time-range
time-range-name] [disable-port | log-input]
Parameters
•
protocol
—The name or the number of an IP protocol. Available protocol
names: icmp, igmp, ip, tcp, egp, igp, udp, hmp, rdp, idpr, ipv6, ipv6:rout,
ipv6:frag, idrp, rsvp, gre, esp, ah, ipv6:icmp, eigrp, ospf, ipinip, pim, l2tp,
isis. To match any protocol use the Ip keyword. (Range: 0–255)
•
source
—Source IP address of the packet.
•
source-wildcard
—Wildcard bits to be applied to the source IP address.
Use 1s in the bit position that you want to be ignored.
•
destination
—Destination IP address of the packet.
•
destination-wildcard
—Wildcard bits to be applied to the destination IP
address. Use 1s in the bit position that you want to be ignored.
•
dscp number
—Specifies the DSCP value.
•
precedence number
—Specifies the IP precedence value.
•
icmp-type
—Specifies an ICMP message type for filtering ICMP packets.
Enter a number or one of the following values: echo-reply, destination-
unreachable, source-quench, redirect, alternate-host-address, echo-
request, router-advertisement, router-solicitation, time-exceeded,