EasyManua.ls Logo

Dasan V8102 - Applying ACL Filters to Interface

Dasan V8102
910 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
User Manual UMN:CLI
V8102
249
7.18.6.4 Applying ACL Filters to Interface
After the IP based access list is defined, it must be applied to the interface (inbound). To
apply the user-defined access list to the interface and specify its priority, use the following
command.
Command
Mode
Description
ip access-group {<1-99> | <100-
199> | <1300-1999> | <2000-
2699> | WORD} in priority {low |
medium | high | highest}
Interface
Applies the user-defined access list to the interface.
1-99: standard IP access list number
1300-1999: standard IP access list number (expanded
range)
100-199: extended access list number
2000-2699: extended access list number (expanded
range)
WORD: IP access list name
in: inbound packets
out: outbound packets
ip access-group {<1-99> | <100-
199> | <1300-1999> | <2000-
2699> | WORD} out
no ip access-group [{<1-99> |
<100-199> | <1300-1999> |
<2000-2699> | WORD} {in | out}]
Removes the user-defined access list from the inter-
face.
After the MAC address-based ACL is defined, it must be applied to the interface (inbound).
To apply the user-defined access list to the interface and specify its priority, use the fol-
lowing command.
Command
Mode
Description
mac access-group {<700-799> |
<1100-1199> | WORD} in priority
{low | medium | high | highest}
Interface
Applies the user-defined MAC access list to the inter-
face.
700-799: extended MAC access-list number
1100-1199: extended MAC access-list number (ex-
panded range)
WORD: MAC access list name
in: inbound packets.
no mac access-group [{<700-
799> | <1100-1199> | WORD} in]
Removes the user-defined MAC access list from the
interface.
One interface can be applied by one IP based ACL and one MAC based ACL. Up to 64 in-
terfaces can be used for the ACL bindings.
To display the configured IP/MAC address-based ACL bindings with an interface, use the
following command.
Command
Mode
Description
show access-group interface [IN-
TERFACE]
Enable
Global
Shows the IP/MAC access group configuration.
i

Table of Contents