Dell Force10 MXL Blade Reference Manual page 116

Ftos command line reference guide for the mxl 10/40gbe switch io module
Hide thumbs Also See for Force10 MXL Blade:
Table of Contents

Advertisement

Defaults
Command Modes
Command
History
116
|
Access Control Lists (ACL)
ip
Enter the keyword
that the access list will permit all IP protocols.
tcp
Enter the keyword
udp
Enter the keyword
source
Enter the IP address of the network or host from which the packets were sent.
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask, when specified in
A.B.C.D format, may be either contiguous or non-contiguous.
any
Enter the keyword
host ip-address
Enter the keyword
operator
(OPTIONAL) Enter one of the following logical operands:
port port
(OPTIONAL) Enter the application layer port number. Enter two port numbers if
using the
Range: 0 to 65535
The following list includes some common TCP port numbers:
destination
Enter the IP address of the network or host to which the packets are sent.
message-type
(OPTIONAL) Enter an ICMP message type, either with the type (and code, if
necessary) numbers or with the name of the message type (ICMP message types are
listed in
Range: 0 to 255 for ICMP type; 0 to 255 for ICMP code
count
(OPTIONAL) Enter the keyword
byte
(OPTIONAL) Enter the keyword
dscp
(OPTIONAL) Enter the keyword
order
(OPTIONAL) Enter the keyword
entry.
Range:
Default:
fragments
Enter the keyword
Not configured
CONFIGURATION-IP ACCESS-LIST-EXTENDED
Version 8.3.16.1
Introduced on MXL 10/40GbE Switch IO Module
ip
to configure a generic IP access list. The keyword
tcp
to configure a TCP access list filter.
udp
to configure a UDP access list filter.
any
to specify that all routes are subject to the filter.
host
followed by the IP address to specify a host IP address.
eq
= equal to
neq
= not equal to
gt
= greater than
lt
= less than
range
= inclusive range of ports (you must specify two ports for the
parameter.)
range
logical operand.
23 = Telnet
20 and 21 = FTP
25 = SMTP
169 = SNMP
Table
6-2).
count
byte
dscp
order
0-254 (where 0 is the highest priority and 254 is the lowest; lower order
numbers have a higher priority)
If the order keyword is not used, the ACLs have the lowest order by
default (255).
fragments
to use ACLs to control packet fragments.
to count packets processed by the filter.
to count bytes processed by the filter.
to match to the IP DSCP values.
to specify the QoS priority for the ACL
ip
specifies
port

Advertisement

Table of Contents
loading

Table of Contents