EasyManua.ls Logo

ProCurve 2610 - Page 237

ProCurve 2610
454 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Access Control Lists (ACLs)
Introduction
For ACL filtering to take effect, configure an ACL and then assign it to the
inbound traffic on a statically configured port or trunk.
Table 9-1. Comprehensive Command Summary
Action Command Page
Configuring Standard
(Numbered) ACLs
ProCurve(config)# [no] access-list < 1-99 > < deny | permit >
< any | host <src-ip-addr > | src-ip-address/mask >
1
[log]
2
9-39
Configuring Extended
(Numbered) ACLs
ProCurve(config)# [no] access-list <100-199> < deny | permit >
ip < any | host <src-ip-addr > | src-ip-address/mask
>
1
[log]
2
9-44
ProCurve(config)# [no] access-list < 100-199 > < deny | permit >
< tcp | udp >
< any | host <src-ip-addr > | src-ip-address/mask >
1
[eq < src-port tcp/udp-id >]
< any | host <dest-ip-addr > | dest-ip-address/mask >
1
9-44
[eq < dest-port tcp/udp-id >]
[log]
2
Configuring Standard
(Named) ACLs
ProCurve(config)# [no] ip access-list standard < name-str | 1-99 >
ProCurve(config-std-nacl)# < deny | permit >
< any | host <src-ip-addr > | src-ip-address/mask >
1
[log]
2
9-50
9-50
Configuring Extended
(Named) ACLs
ProCurve(config)# [no] ip access-list extended < name-str | 100-199 >
ProCurve(config-std-nacl)# < deny | permit > ip
< any | host <src-ip-addr > | src-ip-address/mask >
1
< any | host <dest-ip-addr > | dest-ip-address/mask >
1
[log]
2
9-50
9-50
ProCurve(config-std-nacl)# < deny | permit > < tcp | udp >
< any | host <src-ip-addr > | src-ip-address/mask >
1
[ eq < tcp/udp-port-# | well-known-port-name >]
< any | host <dest-ip-addr > | dest-ip-address/mask >
1
9-50
[ eq < tcp/udp-port-# | well-known-port-name >]
[log]
2
Enabling or Disabling
an ACL
ProCurve(config)# [no] interface < port-list > access-group
< name-str | 1-99 | 100-199 >
9-52
Deleting an ACL from
the Switch
ProCurve(config)# no ip access-list < standard < name-str | 1-99 >>
ProCurve(config)# no ip access-list < extended < name-str | 100 -199 >>
9-53
9-5

Table of Contents