Deny (Ip) - Alcatel OS-LS-6224 User Manual

User guide
Hide thumbs Also See for OS-LS-6224:
Table of Contents

Advertisement

deny (IP)

The deny IP-Access List Configuration mode command denies traffic if the
conditions defined in the deny statement match.
Syntax
deny [disable-port] {any | protocol} {any | {source source-wildcard}}
{any | {destination destination-wildcard}} [dscp number |
ip-precedence number] [in-port port-num | out-port port-num]
deny-icmp [disable-port] {any | {source source-wildcard}} {any |
{destination destination-wildcard}} {any | icmp-type} {any | icmp-code}
[dscp number | ip-precedence number]
deny-igmp [disable-port] {any | {source source-wildcard}}
{any | {destination destination-wildcard}} {any | igmp-type}
[dscp number | ip-precedence number]
deny-tcp [disable-port] {any | {source source-wildcard}} {any|source-port}
{any | {destination destination-wildcard}} {any | destination-port}
[dscp number | ip-precedence number] [flags list-of-flags]
deny-udp [disable-port] {any | {source source-wildcard}} {any| source-port}
{any | {destination destination-wildcard}} {any | destination-port}
[dscp number | ip-precedence number]
Parameters
• disable-port — Specifies the ethernet interface is disabled if the condition
is matched.
• source — Specifies the IP address or host name from which the packet was
sent. Specify any to indicate IP address 0.0.0.0 and mask
255.255.255.255.
• source-wildcard — (Optional for the first type) Specifies wildcard bits by
placing 1s in bit positions to be ignored. Specify any to indicate IP address
0.0.0.0 and mask 255.255.255.255.
• destination — Specifies the IP address or host name to which the packet is
being sent. Specify any to indicate IP address 0.0.0.0 and mask
255.255.255.255.
• destination-wildcard — (Optional for the first type) Specifies wildcard bits by
placing 1s in bit positions to be ignored. Specify any to indicate IP address
0.0.0.0 and mask 255.255.255.255.
• protocol — Specifies the abbreviated name or number of an IP protocol.
• in-port port-num — (Optional) Specifies the output port of the devise. In
case of egress classification this port will be devise input port.
• out-port port-num — (Optional) Specifies the input port of the devise.
• dscp number — Specifies the DSCP value.
• ip-precedence number — Specifies the IP precedence value.
• fragments — Displays the set of conditions would be applied to noninitial
fragments only.
4
ACL Commands
309

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents