EasyManua.ls Logo

Enterasys Matrix DFE-Gold Series - Page 822

Enterasys Matrix DFE-Gold Series
944 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring Access Lists access-list (extended)
24-18 Security Configuration
To apply ACL restrictions to IP, UDP, or ICMP packets:
access-list access-list-number {deny | permit} protocol source [source-wildcard]
[operator [port]] destination [destination-wildcard] [operator [port]]
[tos-extensions][icmp-type [icmp-code] [log]
To apply ACL restrictions to TCP packets:
access-list access-list-number {deny | permit} protocol source [source-wildcard]
[operator [port]] destination [destination-wildcard] [operator [port]]
[tos-extensions][icmp-type [icmp-code] [established] [log]
no access-list access-list-number [entry]
Parameters
accesslistnumber Specifiesanextendedaccesslistnumber.Validvaluesarefrom100to
199.
insert|replaceentry (Optional)Insertsthisnewentrybeforeaspecifiedentryinanexisting
ACL,orreplacesaspecifiedentrywiththisnewentry.
log15000|all EnablesyslogforACLentry
hits.Enablesyslogforsequentialnumbers
ofACLentriesorforallACLentries.
movedestination
source1source2
(Optional)Movesasequenceofaccesslistentriesbeforeanotherentry.
Destinationisthenumberoftheexistingentrybeforewhichthisnew
entrywillbemoved.Source1isasingleentrynumberor
thefirstentry
numberintherangetobemoved.Source2(optional)isthelastentry
numberintherangetobemoved.Ifnotspecified,onlythesource1entry
willbemoved.
deny|permit Deniesorpermitsaccessifspecifiedconditionsaremet.
protocol SpecifiesanIPprotocolforwhich
todenyorpermitaccess.Validvalues
andtheircorrespondingprotocolsare:
•0255‐AnyIPprotocolnumber,aslistedinhttp://www.iana.org/
assignments/protocolnumbers
ip‐AnyInternetprotocol
icmp‐InternetControlMessageProtocol
udp‐UserDatagramProtocol
tcp‐TransmissionProtocol
ah‐AuthenticationHeaderProtocol
esp‐EncapsulationSecurityPayload
gre
‐GenericRouterEncapsulationProtocol
source Specifiesthenetworkorhostfromwhichthepacketwillbesent.Valid
optionsforexpressingsourceare:
•IPaddressorrangeofaddresses(A.B.C.D)
any‐Anysourcehost
hostsource‐IPaddressofasinglesourcehost
sourcewildcard (Optional)Specifiesthebitstoignorein
thesourceaddress.

Table of Contents

Related product manuals