(Named Hardware Acl: Ip Protocol Entry) - Allied Telesis CentreCOM FS980M/9 Command Reference Manual

Centrecom fs980m series fast ethernet managed access switches alliedware plus version 5.4.7-0.x
Hide thumbs Also See for CentreCOM FS980M/9:
Table of Contents

Advertisement

IP
4 H
A
C
V
ARDWARE
CCESS
ONTROL
(
ACL: IP
NAMED HARDWARE
PROTOCOL ENTRY

(named hardware ACL: IP protocol entry)

Overview
Use this command to add an IP protocol type filter entry to the current hardware
access-list. The filter will match on IP packets that have the specified IP protocol
number, and the specified IP and/or MAC addresses. You can use the value any
instead of source or destination IP or MAC address if an address does not matter.
If you specify a sequence number, the switch inserts the new filter at the specified
location. Otherwise, the switch adds the new filter to the end of the access-list.
The no variant of this command removes a filter entry from the current hardware
access-list. You can specify the filter entry for removal by entering either its
sequence number (e.g. no 100), or by entering its filter profile without specifying
its sequence number (e.g. no deny proto 2 192.168.0.0/16 any).
You can find the sequence number by running the
ACLs)
Hardware ACLs will permit access unless explicitly denied by an ACL action.
[<sequence-number>] <action> proto <1-255> <source-ip>
Syntax
<dest-ip> [<source-mac> <dest-mac>] [vlan <1-4094>]
no <sequence-number>
no <action> proto <1-255> <source-ip> <dest-ip> [<source-mac>
<dest-mac>] [vlan <1-4094>]
Table 24-5: Parameters in IP protocol ACL entries
613-50157-01 Rev C
L
(ACL) C
IST
OMMANDS
)
command.
Parameter
Description
<sequence-
The sequence number for the filter entry of the selected access
number>
control list, in the range 1-65535. If you do not specify a sequence
number, the switch puts the entry at the end of the ACL and
assigns it the next available multiple of 10 as its sequence
number. .
<action>
The action that the switch will take on matching packets:
deny
permit
send-to-cpu
proto <1-255>
The IP protocol number to match against, as defined by IANA
(Internet Assigned Numbers Authority
www.iana.org/assignments/protocol-numbers)
See below for a list of IP protocol numbers and their descriptions.
<source-ip>
The source addresses to match against. You can specify a single
host, a subnet, or all source addresses. The following are the valid
formats for specifying the source:
Command Reference for FS980M Series
AlliedWare Plus™ Operating System - Version 5.4.7-0.x
show access-list (IPv4 Hardware
Reject packets that match the
source and destination filtering
specified with this command.
Permit packets that match the
source and destination filtering
specified with this command.
Send matching packets to the CPU.
787

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents