Download Print this page

Centrecom FS980M/9 Command Reference Manual page 774

Fs980m series fast ethernet managed access switches reference for alliedware plus version 5.4.6-2.x

Advertisement

IP
4 H
A
C
V
ARDWARE
CCESS
ONTROL
-
(
ACCESS
LIST
NUMBERED HARDWARE
Mode
Global Configuration
Default
On an interface controlled by a hardware ACL, any traffic that does not explicitly
match a filter is permitted.
Usage
This command creates an ACL for use with hardware classification. Once you have
configured the ACL, use the
apply this ACL to a port or QoS class-map.
ACLs numbered in the range 3000-3699 match on packets that have the specified
source and destination IP addresses.
You can use ACLs to redirect packets, by sending them to the CPU. Use such ACLs
with caution. They could prevent control packets from reaching the correct
destination, such as EPSR healthcheck messages and VCStack messages.
Hardware ACLs will permit access unless explicitly denied by an ACL action.
613-50137-01 Rev A
L
(ACL) C
IST
OMMANDS
ACL
TCP
UDP)
FOR
OR
Parameter
Description
<ip-addr>
<reverse-mask>
<dest-ip>
The destination addresses to match against. You can specify a
single host, a subnet, or all destination addresses. The following
are the valid formats for specifying the destination:
any
host <ip-addr>
<ip-addr>/<prefix>
<ip-addr>
<reverse-mask>
eq <0-65535>
Match on the specified source or destination TCP or UDP port
number.
vlan <1-4094>
The VLAN to match against. The ACL will match against the
specified ID in the packet's VLAN tag.
Command Reference for FS980M Series
AlliedWare Plus™ Operating System - Version 5.4.6-2.x
Match any source IP address within
the specified subnet. Specify the
subnet by entering a reverse mask in
dotted decimal format. For example,
entering "192.168.1.1 0.0.0.255" is
the same as entering 192.168.1.1/24.
Match any destination IP address.
Match a single destination host with
the IP address given by <ip-addr> in
dotted decimal notation.
Match any destination IP address
within the specified subnet. Specify
the subnet by entering the IPv4
address, then a forward slash, then
the prefix length.
Match any destination IP address
within the specified subnet. Specify
the subnet by entering a reverse
mask in dotted decimal format. For
example, entering "192.168.1.1
0.0.0.255" is the same as entering
192.168.1.1/24.
access-group
or the
match access-group
command to
774

Advertisement

loading