EasyManua.ls Logo

Enterasys SecureStack C2

Enterasys SecureStack C2
607 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
access-list (extended)
18-78 Security Configuration
Syntax
To apply ACL restrictions to IP, UDP, ICMP or TCP packets:
access-list access-list-number {deny | permit} protocol source [source-wildcard]
[operator [port]] destination [destination-wildcard]
no access-list access-list-number [entry]
To insert or replace an ACL entry:
access-list access-list-number insert | replace entry
To move entries within an ACL:
access-list access-list-number move destination source1 [source2]
Parameters
accesslistnumber Specif iesanextendedaccesslistnumber.Validvaluesarefrom100to199.
deny|permit Deniesorpermitsaccessifspecifiedconditionsaremet.
protocol SpecifiesanIPprotocolforwhichtodenyorpermitaccess.Validvalues
andtheircorrespondingprotocolsare:
•ip‐AnyInternetprotocol
udp‐User
DatagramProtocol
tcp‐TransmissionControlProtocol
icmp‐InternetControlMessageProtocol
source Specifiesthenetworkorhostfromwhichthepacketwillbesent.Valid
optionsforexpressingsourceare:
•IPaddressorrangeofaddresses(A.B.C.D)
any‐Anysourcehost
hostsource‐IPaddressofasinglesourcehost
sourcewildcard
(Optional)Specifiesthebitstoignoreinthesourceaddress.
operatorport (Optional)AppliesaccessrulestoTCPorUDPsourceordestinationport
numbers.Possibleoperandis:
eqport‐Matchesonlypacketsonagivenportnumber.
destination Specifiesthenetworkorhosttowhichthepacketwillbesent.Valid
options
forexpressingdestinationare:
•IPaddress(A.B.C.D)
any‐Anydestinationhost
hostsource‐IPaddressofasingledestinationhost
destination
wildcard
(Optional)Specifiesthebitstoignoreinthedestinationaddress.
insert|replace
entry
(Optional)Insertsthisnewentrybeforeaspecifiedentryinanexisting
ACL,orreplacesa
specifiedentrywiththisnewentry.

Table of Contents

Related product manuals