Security Network Acl Add - Planet XGSW-28040 User Manual

24-port gigabit with 4 shared sfp 4-port 10g sfp+ managed switch
Hide thumbs Also See for XGSW-28040:
Table of Contents

Advertisement

Security Network ACL Add

Description:
Add or modify Access Control Entry (ACE).
If the ACE ID parameter <ace_id> is specified and an entry with this ACE ID already exists, the ACE will be modified.
Otherwise, a new ACE will be added. If the ACE ID is not specified, the next available ACE ID will be used.
If the next ACE ID parameter <ace_id_next> is specified, the ACE will be placed before this ACE in the list. If the next
ACE ID is not specified, the ACE will be placed last in the list.
If the Switch keyword is used, the rule applies to all ports. If the Port keyword is used, the rule applies to the specified port
only. If the Policy keyword is used, the rule applies to all ports configured with the specified policy. The default is that the
rule applies to all ports.
Syntax:
Security Network ACL Add [<ace_id>] [<ace_id_next>] [(port <port>)] [(policy <policy> <policy_bitmask>)] [<vid>]
[<tag_prio>] [<dmac_type>] [(etype [<etype>] [<smac>] [<dmac>]) | (arp [<sip>] [<dip>] [<smac>] [<arp_opcode>]
[<arp_flags>]) | (ip [<sip>] [<dip>] [<protocol>] [<ip_flags>]) | (icmp [<sip>] [<dip>] [<icmp_type>] [<icmp_code>]
[<ip_flags>]) | (udp [<sip>] [<dip>] [<sport>] [<dport>] [<ip_flags>]) | (tcp [<sip>] [<dip>] [<sport>] [<dport>] [<ip_flags>]
[<tcp_flags>])] [permit|deny] [<rate_limiter>] [<port_redirect>] [<logging>] [<shutdown>]
Parameters:
: ACE ID (1-512), default: Next available ID
<ace_id>
: Next ACE ID (1-512), default: Add ACE last
<ace_id_next>
: Port ACE keyword
port
: Port number or 'all'
<port>
: Policy ACE keyword
policy
: Policy number (0-255)
<policy>
<policy_bitmask>: Policy number bitmask (0x0-0xFF)
: VLAN ID (1-4095) or 'any'
<vid>
: VLAN tag priority (0-7) or 'any'
<tag_prio>
<dmac_type>
: Ethernet Type keyword
etype
: Ethernet Type: 0x600 - 0xFFFF or 'any' but excluding 0x800(IPv4) 0x806(ARP) and 0x86DD(IPv6)
<etype>
<smac>
<dmac>
: ARP keyword
arp
: DMAC type: any|unicast|multicast|broadcast
: Source MAC address ('xx-xx-xx-xx-xx-xx' or 'xx.xx.xx.xx.xx.xx' or 'xxxxxxxxxxxx', x is a hexadecimal
digit) or 'any'
: Destination MAC address ('xx-xx-xx-xx-xx-xx' or 'xx.xx.xx.xx.xx.xx' or 'xxxxxxxxxxxx', x is a
hexadecimal digit) or 'any'
433
User's Manual of XGSW-28040

Advertisement

Table of Contents
loading

Table of Contents