Chapter 4. Access Control List configuration mode
This chapter provides an alphabetic listing of commands that are available in
Access Control List (ACL) configuration mode.
To enter this configuration mode, use the Global
acl
command. While in this mode,
create an ACL. An ACL consists of a sequence of
allow
and
deny
clauses. Each
clause identifies an IP address or range of addresses that allow or that deny access
to a service.
An ACL is associated with a specific DataPower service. An ACL grants access to
the service to only addresses that are defined by the
allow
command. All other
addresses are denied access.
Candidate addresses are evaluated sequentially against each
allow
and
deny
clause
in the ACL. A candidate address is denied or granted access in accordance with the
first clause that matches. Consequently, the order of
allow
and
deny
clauses in the
ACL is vital.
For example, the following ACL fails its intended purpose. The address range that
is specified by the
deny
clause (192.168.14.224 through 192.168.14.255) is granted
access before the
allow
clause.
allow 192.168.14.0/24
deny 192.168.14.0/27
However, as shown in the following example, reversing the sequence of the clauses
achieves the desired effect.
deny 192.168.14.0/27
allow 192.168.14.0/24
An ACL that contains only
deny
clauses effectively disables a service by denying
access to all addresses. To complete an ACL, include the
allow any
clause. This
clause ensures that addresses that are not explicitly denied access are granted
access.
The following example denies access to two ranges of addresses and allows access
to all other addresses.
deny 10.10.10.0/24
deny 172.16.0.0/16
allow any
All of the commands that are listed in “Common commands” on page 2 and most,
but not all, of the commands that are listed in Chapter 114, “Monitoring
commands,” on page 949 are also available in ACL configuration mode.
allow
Identifies IP addresses to grant access.
© Copyright IBM Corp. 1999, 2008
169
Summary of Contents for WebSphere XS40
Page 1: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 2: ......
Page 3: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 44: ...18 Command Reference ...
Page 194: ...168 Command Reference ...
Page 198: ...172 Command Reference ...
Page 206: ...180 Command Reference ...
Page 210: ...184 Command Reference ...
Page 222: ...196 Command Reference ...
Page 232: ...206 Command Reference ...
Page 238: ...212 Command Reference ...
Page 268: ...242 Command Reference ...
Page 272: ...246 Command Reference ...
Page 276: ...250 Command Reference ...
Page 288: ...262 Command Reference ...
Page 292: ...266 Command Reference ...
Page 298: ...272 Command Reference ...
Page 320: ...294 Command Reference ...
Page 322: ...296 Command Reference ...
Page 340: ...314 Command Reference ...
Page 344: ...318 Command Reference ...
Page 352: ...326 Command Reference ...
Page 360: ...334 Command Reference ...
Page 368: ...342 Command Reference ...
Page 376: ...350 Command Reference ...
Page 386: ...360 Command Reference ...
Page 392: ...366 Command Reference ...
Page 396: ...370 Command Reference ...
Page 402: ...376 Command Reference ...
Page 404: ...378 Command Reference ...
Page 408: ...382 Command Reference ...
Page 446: ...420 Command Reference ...
Page 450: ...424 Command Reference ...
Page 456: ...430 Command Reference ...
Page 520: ...494 Command Reference ...
Page 536: ...510 Command Reference ...
Page 550: ...524 Command Reference ...
Page 584: ...558 Command Reference ...
Page 600: ...574 Command Reference ...
Page 605: ... timeout 500 Chapter 63 RADIUS configuration mode 579 ...
Page 606: ...580 Command Reference ...
Page 650: ...624 Command Reference ...
Page 668: ...642 Command Reference ...
Page 704: ...678 Command Reference ...
Page 714: ...688 Command Reference ...
Page 726: ...700 Command Reference ...
Page 734: ...708 Command Reference ...
Page 752: ...726 Command Reference ...
Page 756: ...730 Command Reference ...
Page 804: ...778 Command Reference ...
Page 880: ...854 Command Reference ...
Page 892: ...866 Command Reference ...
Page 912: ...886 Command Reference ...
Page 918: ...892 Command Reference ...
Page 940: ...914 Command Reference ...
Page 946: ...920 Command Reference ...
Page 974: ...948 Command Reference ...
Page 1004: ...978 Command Reference ...
Page 1030: ...1004 Command Reference ...
Page 1032: ...1006 Command Reference ...
Page 1065: ......
Page 1066: ... Printed in USA ...