274
DCS-3950 series Ethernet switch manual
Switch(Config-MacIp-Ext-Nacl-macip_acl)#
15.3.2.15 permit | deny(mac-ip extended)
Command:[no]
{deny|permit}{any-source-mac|{host-source-mac<host_smac>}|{<smac><smac-ma
sk>}}
{any-destination-mac|{host-destination-mac<host_dmac>}|{<dmac><dmac-mask>}}
icmp{{<source><source-wildcard>}|any|{host<source-host-ip>}}
{{<destination><destination-wildcard>}|any-destination|{host-destination
<destination-host-ip>}} [<icmp-type> [<icmp-code>]] [precedence <precedence>]
[tos <tos>][time-range<time-range-name>]
[no]{deny|permit}
{any-source-mac|{host-source-mac<host_smac>}|{<smac><smac-mask>}}
{any-destination-mac|{host-destination-mac<host_dmac>}|{<dmac><dmac-mask>}}
igmp{{<source><source-wildcard>}|any| {host<source-host-ip>}}
{{<destination><destination-wildcard>}|any-destination|{host-destination
<destination-host-ip>}} [<igmp-type>] [precedence <precedence>] [tos
<tos>][time-range<time-range-name>]
[no]{deny|permit}{any-source-mac|{host-source-mac<host_smac>}|
{<smac><smac-mask>}}{any-destination-mac|{host-destination-mac<host_dmac>}|
{<dmac><dmac-mask>}}tcp{{<source><source-wildcard>}|any|
{host<source-host-ip>}}[s-port<port1>]{{<destination>
<destination-wildcard>}|any-destination| {host-destination <destination-host-ip>}}
[d-port <port3>] [ack+fin+psh+rst+urg+syn] [precedence <precedence>
] [tos
<tos>][time-range<time-range-name>]
[no]{deny|permit}{any-source-mac|{host-source-mac<host_smac>}|{<smac>
<smac-mask>}}{any-destination-mac|{host-destination-mac<host_dmac>}|
{<dmac><dmac-mask>}}udp{{<source><source-wildcard>}|any|
{host<source-host-ip>}}[s-port<port1>]{{<destination>
<destination-wildcard>}|any-destination| {host-destination <destination-host-ip>}}
[d-port <port3>] [precedence <precedence>] [tos
<tos>][time-range<time-range-name>]
[no]{deny|permit}{any-source-mac|{host-source-mac<host_smac>}|{<smac>
<smac-mask>}}{any-destination-mac|{host-destination-mac<host_dmac>}|
{<dmac><dmac-mask>}}{eigrp|gre|igrp|ip|ipinip|ospf|{<protocol-num>}}
{{<source><source-wildcard>}|any|{host<source-host-ip>}}
{{<destination><destination-wildcard>}|any-destination|{host-destination
<destination-host-ip>}} [precedence <precedence>] [tos
<tos>][time-range<time-range-name>]
Functions: Define an expansion name MAC-IP ACL rule, ‘No’ form deletes one
expansion numeric MAC-IP ACL access-list rule.
Parameters: num access-list serial No. this is a decimal’s No. from 3100-3199.; deny: if
rules are matching, deny to access; permit: if rules are matching, permit to access;