Additional Filtering Options; Sequence Numbers - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Cli software configuration guide
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

Information About ACLs
All IPv4 ACLs include the following implicit rule:
deny ip any any
This implicit rule ensures that the switch denies unmatched IP traffic.

Additional Filtering Options

You can identify traffic by using additional options. IPv4 ACLs support the following additional filtering
options:
• Layer 4 protocol
• TCP and UDP ports
• ICMP types and codes
• IGMP types
• Precedence level
• Differentiated Services Code Point (DSCP) value
• TCP packets with the ACK, FIN, PSH, RST, SYN, or URG bit set
• Established TCP connections
IPv6 ACLs support the following additional filtering options:
• Layer 4 protocol
• Authentication Header Protocol
• Encapsulating Security Payload
• Payload Compression Protocol
• Stream Control Transmission Protocol (SCTP)
• SCTP, TCP, and UDP ports
• ICMP types and codes
• IGMP types
• Flow label
• DSCP value
• TCP packets with the ACK, FIN, PSH, RST, SYN, or URG bit set
• Established TCP connections
• Packet length

Sequence Numbers

The switch supports sequence numbers for rules. Every rule that you enter receives a sequence number, either
assigned by you or assigned automatically by the switch. Sequence numbers simplify the following ACL
tasks:
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
Additional Filtering Options
281

Advertisement

Table of Contents
loading

Table of Contents