Allied Telesis CentreCOM FS980M/9 Command Reference Manual page 781

Centrecom fs980m series fast ethernet managed access switches alliedware plus version 5.4.7-0.x
Hide thumbs Also See for CentreCOM FS980M/9:
Table of Contents

Advertisement

IP
4 H
A
C
V
ARDWARE
CCESS
ONTROL
(
ACL: ICMP
NAMED HARDWARE
Mode
IPv4 Hardware ACL Configuration (accessed by running the command
hardware (named hardware
Default
On an interface controlled by a hardware ACL, any traffic that does not explicitly
match a filter is permitted.
Usage
To use this command, first run the command
hardware ACL)
awplus(config-ip-hw-acl)#.
Then use this command (and the other "named hardware ACL: entry" commands)
to add filter entries. You can add multiple filter entries to an ACL. You can insert a
new filter entry into the middle of an existing list by specifying the appropriate
sequence number. If you do not specify a sequence number, the switch puts the
entry at the end of the ACL and assigns it the next available multiple of 10 as its
sequence number.
Then use the
to a port or QoS class-map. Note that the ACL will only apply to incoming data
packets.
You can use ACLs to redirect packets, by sending them to the CPU. Use such ACLs
with caution. They could prevent control packets from reaching the correct
destination, such as EPSR healthcheck messages and VCStack messages.
Examples
To add an access-list filter entry with a sequence number of 100 to the access-list
named "my-list" that will permit ICMP packets with a source address of
192.168.1.0/24, any destination address and an ICMP type of 5, use the commands:
awplus#
awplus(config)#
awplus(config-ip-hw-acl)#
icmp-type 5
To remove an access-list filter entry with a sequence number of 100 from the
access-list named "my-list", use the commands:
awplus#
awplus(config)#
awplus(config-ip-hw-acl)#
613-50157-01 Rev C
L
(ACL) C
IST
OMMANDS
)
ENTRY
Parameter
Description
13
14
15
16
17
18
vlan <1-4094>
The VLAN to match against. The ACL will match against the
specified ID in the packet's VLAN tag.
and enter the desired access-list name. This changes the prompt to
access-group
configure terminal
access-list hardware my-list
configure terminal
access-list hardware my-list
Command Reference for FS980M Series
AlliedWare Plus™ Operating System - Version 5.4.7-0.x
Timestamp requests.
Timestamp replies.
Information requests.
Information replies.
Address mask requests.
Address mask replies.
ACL))
access-list hardware (named
or the
match access-group
100 permit icmp 192.168.1.0/24 any
no 100
access-list
command to apply this ACL
781

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents