Commands Contained In The Access-List Extended Mode - ADTRAN 5000 Series Command Reference Manual

Adtran network device command reference guide
Table of Contents

Advertisement

Command Reference Guide
<icmp-code>
<icmp-message>
Default Values
By default, all AOS security features are disabled and there are no configured access lists.
Applicable Platforms
This command applies to the NetVanta 300, 1000, 1000R, 2000, 3000, 4000, and 5000 and
Total Access 900 Series units.
Command History
Release 2.1
Functional Notes
Access control lists (ACLs) are used as packet selectors by other AOS systems; by themselves they do
nothing. ACLs are composed of an ordered list of entries with an implicit deny all at the end of each list. An
ACL entry contains two parts: an action (permit or deny) and a packet pattern. A permit ACL is used to
allow packets (meeting the specified pattern) to enter the router system. A deny ACL advances the AOS to
the next access policy entry. The AOS provides two types of ACLs: standard and extended. Standard
ACLs allow source IP address packet patterns only. Extended ACLs may specify patterns using most fields
in the IP header and the TCP or UDP header.
ACLs are performed in order from the top of the list down. Generally, the most specific entries should be at
the top and the most general at the bottom.
The following commands are contained in the access-list extended mode:
remark
log
61200990L1-35E
Optional. Filters ICMP packets that are filtered using the ICMP message type
(using the <icmp-type> keyword) may also be filtered using the ICMP message
code (valid range: 0 to 255).
An <icmp-type> must be specified when entering an <icmp-code>.
Optional. Filters packets using ICMP descriptive message rather than the
corresponding type and code associations.
Command was introduced.
Associates a descriptive tag (up to 80 alphanumeric characters enclosed in
quotation marks) to the access list. Enter a functional description for the list such
as "This list blocks all outbound web traffic".
Logs a message (if debug access-list is enabled for this access list) when the
access list finds a packet match.
Copyright © 2005 ADTRAN
Global Configuration Mode Command Set
347

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents