
Brocade Mobility RFS7000-GR CLI Reference Guide 367
53-1001945-01
Extended ACL Config Commands
14
Usage Guidelines
Use this command to permit traffic between network’s/host’s based on the protocol type selected
in the access list configuration. The following protocols are supported:
• ip
• icmp
• tcp
• udp
The last ACE in the access list is an implict deny statement.
permit {icmp}
{source/source-mask
A.B.C.D/M| host sourcehost
| any} {destination/
destination-maskA.B.C.D/M
| host destinationhosthost |
any}
[icmp-type |
[icmp-type icmp-code]] [log]
[rule-precedence
access-list-entry precedence]
Use with the permit command to allow icmp packets.
• permit – The keyword specifies permit action on an ACL.
• {icmp} – Specifies icmp as the protocol.
• {source/source-mask A.B.C.D/M| host sourcehost | any} – The keyword source
is the source IP address of the network or host in dotted decimal. Source-mask
is the network mask. For example, 10.1.1.10/24 indicates the first 24 bits of
the source IP are used for matching.
• any is an abbreviation for source IP of 0.0.0.0 and source-mask bits equal
to 0.
• host is an abbreviation for exact source (A.B.C.D) and source-mask bits
equal to 32.
• {destination/ destination-maskA.B.C.D/M | host destinationhost | any} – The
destination host IP address or destination network address.
• [icmp-type |icmp-type icmp-code] – ICMP type value from 0 to 255. Valid only
for protocol type icmp. ICMP code value from 0 to 255. Valid only for protocol
type icmp.
• [log] – Generates log messages when the packet coming from the interface
matches the ACL entry. Log messages are generated only for router ACLs.
• [rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.
permit{tcp|udp}
{source/source-mask
A.B.C.D/M| host sourcehost
| any} [operator source-port]
{destination/destination-ma
sk | host destinationhost |
any}
[operator destination-port]
[log]
[rule-precedence
access-list-entry precedence]
Use with the permit command to allow tcp or udp packets.
• permit – The keyword specifies permit action on an ACL.
• {tcp|udp} – Specify tcp or udp as the protocol.
• {source/source-mask A.B.C.D/M| host sourcehost | any} – source is the source
IP address of the network or host in dotted decimal. Source-mask is the
network mask. For example, 10.1.1.10/24 indicates the first 24 bits of the
source IP are used for matching.
• any is an abbreviation for source IP of 0.0.0.0 and source-mask bits equal
to 0.
• host is an abbreviation for exact source (A.B.C.D) and source-mask bits
equal to 32.
• [operator source-port] – Valid only for tcp or udp protocols. Valid values are eq
and range.
• range – Specify the protocol range (starting and ending protocol
numbers).
• port – Valid Port number.
• {destination/destination-mask | host destinationhost | any} – The destination
host IP address or destination network address.
• [operator destination-port] – Specify the destination port.
• [log] – Generates log messages when the packet coming from the interface
matches the ACL entry. Log messages are generated only for router ACLs.
• [rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.
Comentarios a estos manuales