Allied Telesis CentreCOM FS980M/9 Command Reference Manual page 818

Centrecom fs980m series fast ethernet managed access switches alliedware plus version 5.4.7-0.x
Hide thumbs Also See for CentreCOM FS980M/9:
Table of Contents

Advertisement

IP
4 S
A
C
V
OFTWARE
CCESS
ONTROL
(
-
IP
ACCESS
LIST EXTENDED
FILTER
Mode
Extended ACL Configuration
Default
Any traffic controlled by a software ACL that does not explicitly match a filter is
denied.
Usage
An ACL can be configured with multiple ACL filters using sequence numbers. If the
sequence number is omitted, the next available multiple of 10 will be used as the
sequence number for the new filter. A new ACL filter can be inserted into the
middle of an existing list by specifying the appropriate sequence number.
NOTE
(extended numbered)
the required access control list number, or name - but with no further parameters
selected.
Software ACLs will deny access unless explicitly permitted by an ACL action.
Example 1
First use the following commands to enter the IPv4 Extended ACL Configuration
mode and define a numbered extended access-list 101:
[list-number]
awplus#
awplus(config)#
awplus(config-ip-ext-acl)#
Then use the following commands to add a new entry to the numbered extended
access- list 101 that will reject packets from 10.0.0.1 to 192.168.1.1:
awplus(config-ip-ext-acl)#
192.168.1.1
awplus(config-ip-ext-acl)#
Example 2
First use the following commands to enter the IPv4 Extended ACL Configuration
mode and define a named access-list called my-acl:
[list-name]
awplus#
awplus(config)#
awplus(config-ip-ext-acl)#
613-50157-01 Rev C
L
(ACL) C
IST
OMMANDS
)
Parameter
Description
<destination> The destination address of the packets. You can specify a single
host, a subnet, or all destinations. The following are the valid
formats for specifying the destination:
any
host<ip-addr>
<ip-addr>
<reverse-mask>
: The access control list being configured is selected by running the
command or the
configure terminal
access-list 101
configure terminal
access-list extended my-acl
Command Reference for FS980M Series
AlliedWare Plus™ Operating System - Version 5.4.7-0.x
Matches any destination IP address.
Matches a single destination host with the
IP address given by <ip-addr> in dotted
decimal notation.
Alternatively, enter an IPv4 address
followed by a reverse mask in dotted
decimal format. For example, enter
192.168.1.1 0.0.0.255.
access-list extended (named)
deny ip host 10.0.0.1 host
20 permit ip any any
access-list
command, with
818

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents