Brocade Mobility RFS7000-GR Controller CLI Reference Guide Manual de usuario Pagina 368

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 607
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 367
354 Brocade Mobility RFS7000-GR CLI Reference Guide
53-1001945-01
Extended ACL Config Commands
14
Parameters
deny {ip}
{source/source-mask
A.B.C.D/M| host sourcehost
| any}
{destination/destination-ma
skA.B.C.D/M | host
destinationhost | any} [log]
[rule-precedence
access-list-entry precedence]
Use with a deny command to reject IP packets.
deny – The keyword specifies deny action on an ACL.
{ip} – Specifies IP (to match any protocol).
{A.B.C.D/M | host | any} – A.B.C.D is the source IP address of the network or
host in dotted decimal format. M is the network mask. For example,
10.1.1.10/24 indicates the first 24 bits of the source IP are used for matching.
any is an abbreviation for a source IP of 0.0.0.0 and source-mask bits
equal to 0.
host is an abbreviation for exact source (A.B.C.D) and source-mask bits
equal to 32.
{A.B.C.D/M | host destinationhost | any} – The destination host IP address or
destination network address.
[log] – Generates log messages when the packet coming from the interface
matches the ACL entry. Log messages are generated only for router ACLs.
[rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.
deny {icmp}
{source/source-mask
A.B.C.D/M| host sourcehost
| any} {destination/
destination-maskA.B.C.D/M
A.B.C.D/M | host destination
| any} [icmp-type |
[icmp-type icmp-code]] [log]
[rule-precedence
access-list-entry precedence]
Use with deny command to reject icmp packets.
deny – The keyword specifies deny action on an ACL.
{icmp} – Specifies icmp as the protocol.
{source/source-maskA.B.C.D/M | host sourcehost | any} sourceA.B.C.D is
the source IP address of the network or host in dotted decimal format.
Source-maskM is the network mask. For example, 10.1.1.10/24 indicates the
first 24 bits of the source IP are used for matching.
any is an abbreviation for source IP of 0.0.0.0 and source-mask bits equal
to 0.
host is an abbreviation for exact source (A.B.C.D) and source-mask bits
equal to 32.
{destination/ destination-maskA.B.C.D/M | host destination | any} – The
destination host IP address or destination network address.
[icmp-type |icmp-type icmp-code] – ICMP type value from 0 to 255. Valid only
for protocol type icmp. ICMP code value from 0 to 255. Valid only for the
protocol type icmp.
[log] – Generates log messages when the packet coming from the interface
matches an ACL entry. Log messages are generated only for router ACLs.
[rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.
Vista de pagina 367
1 2 ... 363 364 365 366 367 368 369 370 371 372 373 ... 606 607

Comentarios a estos manuales

Sin comentarios