Brocade FastIron Ethernet Switch Security Configuration Gu Manual de usuario Pagina 124

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 396
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 123
Syntax: [no] ip access-list [ standard | extended ] ACL-num
Syntax:remark comment-text
For ACL-num , enter the number of the ACL.
The comment-text can be up to 128 characters in length. The comment must be entered separately
from the actual ACL entry; that is, you cannot enter the ACL entry and the ACL comment with the
same access-list or ip access-list command. Also, in order for the remark to be displayed correctly in
the output of show commands, the comment must be entered immediately before the ACL entry it
describes. Note that an ACL comment is tied to the ACL entry immediately following the comment.
Therefore, if the ACL entry is removed, the ACL comment is also removed.
The standard | extended parameter indicates the ACL type.
Adding a comment to an entry in a named ACL
To add comments to entries in a named ACL, enter commands such as the following.
device(config)#ip access-list extended TCP/UDP
device(config-ext-nACL)#remark The following line permits TCP packets
device(config-ext-nACL)#permit tcp 192.168.4.40/24 2.2.2.2/24
device(config-ext-nACL)#remark The following permits UDP packets
device(config-ext-nACL)#permit udp 192.168.2.52/24 2.2.2.2/24
device(config-ext-nACL)#deny ip any any
Syntax: [no] access-list [ standard | extended ] ACL-name remark comment-text
The standard | extended parameter indicates the ACL type.
For ACL-name, enter the name of the ACL.
The comment-text can be up to 128 characters in length. The comment must be entered separately
from the actual ACL entry; that is, you cannot enter the ACL entry and the ACL comment with the
same ip access-list command. Also, in order for the remark to be displayed correctly in the output of
show commands, the comment must be entered immediately before the ACL entry it describes. Note
that an ACL comment is tied to the ACL entry immediately following the comment. Therefore, if the
ACL entry is removed, the ACL comment is also removed.
Deleting a comment from an ACL entry
To delete a comment from an ACL entry, enter commands such as the following.
device(config)#ip access-list standard 99
device(config)#no remark The following line permits TCP packets
Syntax: [no] remark comment-text
Viewing comments in an ACL
You can use the following commands to display comments for ACL entries:
show running-config
show access-list
show ip access-list
Adding a comment to an entry in a named ACL
124 FastIron Ethernet Switch Security Configuration Guide
53-1003088-03
Vista de pagina 123
1 2 ... 119 120 121 122 123 124 125 126 127 128 129 ... 395 396

Comentarios a estos manuales

Sin comentarios