Edge-Core ES3528MV2 Management Manual page 953

Edge-core 28-port fast ethernet layer 2 switch
Table of Contents

Advertisement

This command adds a rule to a Standard IPv4 ACL. The rule sets a filter
permit, deny
condition for packets emanating from the specified source. Use the no
(Standard IP ACL)
form to remove a rule.
S
YNTAX
{permit | deny} {any | source bitmask | host source}
no {permit | deny} {any | source bitmask | host source}
D
EFAULT
None
C
OMMAND
Standard IPv4 ACL
C
OMMAND
New rules are appended to the end of the list.
Address bit masks are similar to a subnet mask, containing four
integers from 0 to 255, each separated by a period. The binary mask
uses 1 bits to indicate "match" and 0 bits to indicate "ignore." The
bitmask is bitwise ANDed with the specified source IP address, and then
compared with the address for each IP packet entering the port(s) to
which this ACL has been assigned.
E
XAMPLE
This example configures one permit rule for the specific address 10.1.1.21
and another rule for the address range 168.92.16.x – 168.92.31.x using a
bitmask.
Console(config-std-acl)#permit host 10.1.1.21
Console(config-std-acl)#permit 168.92.16.0 255.255.240.0
Console(config-std-acl)#
R
ELATED
access-list ip (952)
Time Range (762)
[time-range time-range-name]
any – Any source IP address.
source – Source IP address.
bitmask – Dotted decimal number representing the address bits to
match.
host – Keyword followed by a specific IP address.
time-range-name - Name of the time range.
(Range: 1-30 characters)
S
ETTING
M
ODE
U
SAGE
C
OMMANDS
– 953 –
| Access Control Lists
C
26
HAPTER
IPv4 ACLs

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Es3528mv2-dc

Table of Contents