(Access-List Hardware Ip Protocol Filter) - Allied Telesis x310-26FT Command Reference Manual

X310 series stackable access switches for alliedware plus version 5.4.6-1.x
Table of Contents

Advertisement

IP
4 H
A
C
V
ARDWARE
CCESS
ONTROL
(
-
IP
ACCESS
LIST HARDWARE
PROTOCOL FILTER

(access-list hardware IP protocol filter)

Overview
Use this ACL filter to add an IP protocol type filter entry to the current hardware
access-list. The filter will match on any IP packet that has the specified source and
destination IP addresses and IP protocol type, or has the optionally specified
source and destination MAC addresses. The parameter any may be specified if an
address does not matter. If a sequence number is specified, the new filter is
inserted at the specified location. Otherwise, the new filter is added at the end of
the access-list.
The no variant of this command removes an IP protocol type filter entry from the
current hardware access-list. You can specify the IP protocol type filter entry for
removal by entering either its sequence number (e.g. no 10), or by entering its IP
protocol type filter profile without specifying its sequence number.
Note that the sequence number can be found by running the
Hardware ACLs)
Syntax
[<sequence-number>]
{deny|permit|send-to-cpu|copy-to-cpu|copy-to-mirror}
[any|ip|proto]
{any|ip|proto <ip-protocol>} 
{<source>|dhcpsnooping|any} {<destination>|any} 
[mac {<mac-source-address> <mac-source-mask>|any]
{<mac-destination-address> <mac-destination-mask>|any} 
no {deny|permit|send-to-cpu|copy-to-cpu|copy-to-mirror}
{any|ip|proto <ip-protocol>} 
{<source>|dhcpsnooping} {<destination>|any} 
[mac {<mac-source-address> <mac-source-mask>|any]
{<mac-destination-address> <mac-destination-mask>|any} 
no <sequence-number>
C613-50103-01 REV A
L
(ACL) C
IST
OMMANDS
)
command.
Parameter
<sequence-number>
deny
permit
send to cpu
copy to cpu
copy to mirror
ip
any
Command Reference for x310 Series
AlliedWare Plus™ Operating System - Version 5.4.6-1.x
Description
<1-65535>
The sequence number for the filter entry of the selected
access control list.
Access-list rejects packets of the type specified.
Access-list allows packets of the type specified
Specify packets to send to the CPU.
Specify packets to copy to the CPU.
Specify packets to copy to the mirror port.
IP packets.
Any packet.
show access-list (IPv4
1373

Advertisement

Table of Contents
loading

This manual is also suitable for:

X310-26fpX310-50fpX310-50ft

Table of Contents