HP ProCurve 5300xl Series Management Manual page 350

Advanced traffic
Hide thumbs Also See for ProCurve 5300xl Series:
Table of Contents

Advertisement

Access Control Lists (ACLs) for the Series 5300xl Switches
Introduction
Table 9-1.
Comprehensive Command Summary
Action
Command
Configuring Standard HPswitch(config)# [no] access-list < 1-99 > < deny | permit >
(Numbered) ACLs
Configuring Extended HPswitch(config)# [no] access-list <100-199> < deny | permit >
(Numbered) ACLs
HPswitch(config)# [no] access-list < 100-199 > < deny | permit >
Configuring Standard HPswitch(config)# [no] ip access-list standard < name-str | 1-99 >
(Named) ACLs
HPswitch(config-std-nacl)# < deny | permit >
Configuring Extended HPswitch(config)# [no] ip access-list extended < name-str | 100-199 >
(Named) ACLs
HPswitch(config-std-nacl)# < deny | permit > ip
HPswitch(config-std-nacl)# < deny | permit > < tcp | udp >
Enabling or Disabling
HPswitch(config)# [no] vlan < vid > ip access-group
an ACL
1
The mask can be in either dotted-decimal notation (such as 0.0.15.255) or CIDR notation (such as /20).
2
The [log] function applies only to "deny" ACLs, and generates a message only when there is a "deny" match.
9-4
For ACL filtering to take effect, configure an ACL and then assign it to either
the inbound or outbound traffic on a statically configured VLAN on the switch.
(Except for ACEs that screen traffic to an IP address on the switch itself, ACLs
assigned to VLANs can operate only while IP routing is enabled. Refer to
"Notes on IP Routing" on page 9-11.)
< any | host <src-ip-addr > | src-ip-address/mask >
2
[log]
ip < any | host <src-ip-addr > | src-ip-address/mask >
2
[log]
< tcp | udp >
< any | host <src-ip-addr > | src-ip-address/mask >
[operator < src-port tcp/udp-id >]
< any | host <dest-ip-addr > | dest-ip-address/mask >
[operator < dest-port tcp/udp-id >]
2
[log]
< any | host <src-ip-addr > | src-ip-address/mask >
2
[log]
< any | host <src-ip-addr > | src-ip-address/mask >
< any | host <dest-ip-addr > | dest-ip-address/mask >
2
[log]
< any | host <src-ip-addr > | src-ip-address/mask >
[operator < src-port tcp/udp-id >]
< any | host <dest-ip-addr > | dest-ip-address/mask >
[operator < dest-port tcp/udp-id >]
2
[log]
< name-str | 1-99 | 100-199 > < in |out >
Page
9-3
1
3
9-3
1
8
1
1
9-4
4
1
1
1
1
1
9-4
6

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents