Allied Telesis CentreCOM FS980M/9 Command Reference Manual page 814

Centrecom fs980m series fast ethernet managed access switches alliedware plus version 5.4.7-0.x
Hide thumbs Also See for CentreCOM FS980M/9:
Table of Contents

Advertisement

IP
4 S
A
C
V
OFTWARE
CCESS
ONTROL
-
(
ACCESS
LIST
EXTENDED NUMBERED
Mode
Global Configuration
Default
Any traffic controlled by a software ACL that does not explicitly match a filter is
denied.
Usage
Use this command when configuring access-list for filtering IP software packets.
You can either create access-lists from within this command, or you can enter
access-list followed by only the number. Entering only the number moves you to
the IPv4 Extended ACL Configuration mode for the selected access-list. From there
you can configure your access-lists by using the commands
ICMP
filter).
Note that packets must match both the source and the destination details.
NOTE
Examples
You can enter the extended ACL in the Global Configuration mode together with
the ACL filter entry on the same line, as shown below:
awplus#
awplus(config)#
any
Alternatively, you can enter the extended ACL in Global Configuration mode
before specifying the ACL filter entry in the IPv4 Extended ACL Configuration
mode, as shown below:
awplus#
awplus(config)#
awplus(config-ip-ext-acl)#
613-50157-01 Rev C
L
(ACL) C
IST
OMMANDS
)
Parameter
Description
<destination>
The destination address of the packets. You can specify a single
host, a subnet, or all destinations. The following are the valid
formats for specifying the destination:
any
host<ip-addr>
<ip-addr>
<reverse-mask>
filter),
(access-list extended IP
: Software ACLs will deny access unless explicitly permitted by an ACL action.
configure terminal
access-list 101 deny ip 172.16.10.0 0.0.0.255
configure terminal
access-list 101
Command Reference for FS980M Series
AlliedWare Plus™ Operating System - Version 5.4.7-0.x
Matches any destination IP address.
Matches a single destination host with the
IP address given by <ip-addr> in dotted
decimal notation.
An IPv4 address, followed by a reverse
mask in dotted decimal format. For
example, entering 192.168.1.1
0.0.0.255 is the same as entering
192.168.1.1/24. This matches any
destination IP address within the specified
subnet.
filter), and
(access-list extended IP protocol
deny ip 172.16.10.0 0.0.0.255 any
(access-list extended
814

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents