D-Link DI-1750 Reference Manual page 200

Hide thumbs Also See for DI-1750:
Table of Contents

Advertisement

(20)udp UDP transactions
Please Input the code of command to be excute(0-20):3
input 3,Select icmp
input 15,Select raw
input 13,Select packet
input 19,Select tcp
input 20,Select udp
Will you excute it? (Y/N):y
6.8 Filter IP Packets
6.8.1 Filter IP Packets
Packet filtering helps control packet movement through the network. Such control can help limit
network traffic and restrict network use by certain users or devices. To permit or deny packets from
crossing specified interfaces, D-Link provides access lists. You can use access lists in the following
ways:
♦ To control the transmission of packets on an interface
♦ To control virtual terminal line access
♦ To restrict contents of routing updates
This section summarizes how to create IP access lists and how to apply them.
An IP access list is a sequential collection of permission and forbiddance conditions that apply to IP
addresses. The D-Link IOS software tests addresses against the conditions in an access list one by
one. The first match determines whether the software accepts or rejects the address. Because the
software stops testing conditions after the first match, the order of the conditions is critical. If no
conditions match, the software rejects the address.
The two main tasks involved in using access lists are as follows:
(1)
Create an access list by specifying an access list number or name and access conditions.
(2)
Apply the access list to interfaces.
Follwing chapters describe the handling of the two tasks in detail.
6.8.2 Create Standard and Extended Access Lists
Note:
The standard access list can not have the same name with the extended access list.
To create a standard access list, use one of the following commands in global configuration directory:
ip access-list standard name
{source
deny
any}[log]
[source-mask] | any}[log]
Quit
Step1:
[DEFAULT@router /config/]#ip
(00)access-list
(01)as-path
(02)community-list
......
Please Input the code of command to be excute(0-20): 0
input 0,Select access-list option ,prompt is as below:
Command
|
[source-mask]
or
{source
permit
Named access-list
BGP as-path access list definition
Community attribute list definition
Model Name
Function
Use the name to define a standard IP access list.
In standard access-list configuration mode, specify one
or more conditions allowed or denied. This determines
whether the packet is passed or dropped.
Quit the access-list configuration mode.
- 198 -

Advertisement

Table of Contents
loading

This manual is also suitable for:

Di-2621Di-2630Di-3660

Table of Contents