38
C613-50631-01 Rev A Command Reference for IE340 Series 1939
AlliedWare Plus™ Operating System - Version 5.5.3-0.x
IPv4 Hardware
Access Control List
(ACL) Commands
Introduction
Overview This chapter provides an alphabetical reference of IPv4 Hardware Access Control
List (ACL) commands. It contains detailed command information and command
examples about IPv4 hardware ACLs, which you can apply directly to interfaces
using the access-group command.
To apply ACLs to an LACP channel group, apply it to all the individual switch ports
in the channel group. To apply ACLs to a static channel group, apply it to the static
channel group itself.
Most ACL command titles include information in parentheses:
• When the command title ends with words in parentheses, these words
indicate usage instead of keywords to enter into the CLI. For example, the
title access-list (numbered hardware ACL for ICMP) indicates that the
command is used to create an ACL with the syntax:
access-list <3000-3699> <action> icmp <source-ip> <dest-ip>
[icmp-type <number>] [vlan <1-4094>]
• When the command title is completely surrounded by parentheses, the title
indicates the type of ACL filter instead of keywords to enter into the CLI. For
example, the title (named hardware ACL: ICMP entry) represents a
command with the syntax:
[<sequence-number>] <action> icmp <source-ip> <dest-ip>
[icmp-type <number>] [vlan <1-4094>]
Hardware ACLs will permit access unless explicitly denied by an ACL action.
Sub-modes Many of the ACL commands operate from sub-modes that are specific to particular
ACL types. The following table shows the CLI prompts at which ACL commands are
entered.