Deny (Ip) - Alcatel OmniStack LS 6248 User Manual

Os-ls-6200 series
Hide thumbs Also See for OmniStack LS 6248:
Table of Contents

Advertisement

4
Command Line Interface

deny (IP)

The
IP-Access List Configuration mode command denies traffic if the
deny
conditions defined in the deny statement match.
Syntax
[
deny
disable-port
{destination destination-wildcard}} [
ip-precedence] [
deny-icmp [disable-port] {any|{source source-wildcard}} {any|{destination
destination-wildcard}} {any|icmp-type} {any|icmp-code} [dscp number |
ip-precedence number]
deny-igmp [disable-port] {any|{source source-wildcard}} {any|{destination
destination-wildcard}} {any|igmp-type} [dscp number | ip-precedence number]
deny-tcp [disable-port] {any|{ source source-wildcard}} {any|source-port}
{any|{ destination destination-wildcard}} {any|destination-port} [dscp number |
ip-precedence number] [flags list-of-flags]
deny-udp [disable-port] {any|{ source source-wildcard}} {any| source-port}
{any|{destination destination-wildcard}} {any|destination-port} [dscp number |
ip-precedence number]
Parameters
• disable-port — Specifies the ethernet interface is disabled if the condition is
matched.
• source — Specifies the IP address or host name from which the packet was
sent. Specify
255.255.255.255.
• source-wildcard — (Optional for the first type) Specifies wildcard bits by
placing 1s in bit positions to be ignored. Specify
0.0.0.0 and mask 255.255.255.255.
• destination — Specifies the IP address or host name to which the packet is
being sent. Specify
255.255.255.255.
• destination-wildcard — (Optional for the first type) Specifies wildcard bits by
placing 1s in bit positions to be ignored. Specify
0.0.0.0 and mask 255.255.255.255.
• protocol — Specifies the abbreviated name or number of an IP protocol.
• in-port port-num — (Optional) Specifies the output port of the devise. In
case of egress classification this port will be devise input port.
• out-port port-num — (Optional) Specifies the input port of the devise.
• dscp number — Specifies the DSCP value.
• ip-precedence number — Specifies the IP precedence value.
• fragments — Displays the set of conditions would be applied only to
noninitial fragments.
• icmp-type — Specifies an ICMP message type for filtering ICMP packets.
304
] {
| protocol} {
any
port-num |
in-port
out-port
to indicate IP address 0.0.0.0 and mask
any
to indicate IP address 0.0.0.0 and mask
any
| {source source-wildcard}} {
any
dscp number |
dscp
port-num]
any
any
|
any
ip-precedence
to indicate IP address
to indicate IP address

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents