Access-List (Numbered Hardware Acl For Tcp Or Udp) - Allied Telesis x510-28GTX Command Reference Manual

Stackable gigabit edge switches x510 series
Table of Contents

Advertisement

IP
4 H
A
C
V
ARDWARE
CCESS
ONTROL
-
(
ACCESS
LIST
NUMBERED HARDWARE
access-list (numbered hardware ACL for TCP
or UDP)
Overview
This command creates an access-list for use with hardware classification. The
access-list will match on TCP or UDP packets that have the specified source and
destination IP addresses and optionally, port values. You can use the value any
instead of source or destination IP address if an address does not matter.
Once you have configured the ACL, you can use the
access-group
You can use the optional vlan parameter to match tagged (802.1q) packets.
The no variant of this command removes the specified IP hardware access-list.
access-list <3000-3699> <action> {tcp|udp} <source-ip>
Syntax
[<source-ports>] <dest-ip> [<dest-ports>] [vlan <1-4094>]
no access-list <3000-3699>
C613-50170-01 Rev B
L
(ACL) C
IST
OMMANDS
ACL
TCP
UDP)
FOR
OR
command to apply this ACL to a port, VLAN or QoS class-map.
Parameter
Description
<3000-3699>
An ID number for this hardware IP access-list.
<action>
The action that the switch will take on matching packets:
deny
permit
copy-to-cpu
copy-to-mirror
send-to-mirror
send-to-vlan-port
vlan <vid> port
<port-number>
send-to-cpu
tcp
Match against TCP packets.
udp
Match against UDP packets.
Command Reference for x510 Series
AlliedWare Plus™ Operating System - Version 5.4.7-1.x
access-group
or the
Reject packets that match the
source and destination filtering
specified with this command.
Permit packets that match the
source and destination filtering
specified with this command.
Send a copy of matching packets to
the CPU.
Send a copy of matching packets to
the mirror port.
Use the
mirror interface
command
to configure the mirror port.
Send matching packets to the
mirror port.
Use the
mirror interface
command
to configure the mirror port.
Send matching packets to the
specified port, tagged with the
specified VLAN. The specified port
must belong to the specified VLAN.
Send matching packets to the CPU.
match
1483

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents