Command Reference ACL Commands
[sn] deny icmp {source source-wildcard | host source | any} {destination destination-wildcard |
host destination | any} [icmp-type] [[icmp-type [icmp-code]] | [icmp-message]] [precedence
precedence] [tos tos] [fragment] [time-range time-range-name]
Transmission Control Protocol (TCP)
[sn] deny udp {source source –wildcard | host source | any} [ operator port [port]] {destination
destination-wildcard | host destination | any} [operator port [port]] [precedence precedence] [tos
tos] [fragment] [range lower upper] [time-range time-range-name]
User Datagram Protocol (UDP)
[sn] deny udp
{source source –wildcard | host source | any} [ operator port [port]] {destination
destination-wildcard | host destination | any} [operator port [port]] [precedence precedence] [tos
tos] [fragment] [range lower upper] [time-range time-range-name]
Extended MAC ACL
[sn] deny {any | host source-mac-address}{any | host destination-mac-address} [ethernet-type][cos
[out] [inner in]]
Extended expert ACL
[sn] deny[protocol | [ethernet-type][ cos [out] [inner in]]] [[VID [out][inne
r in]]] {source
source-wildcard | host source | any}{host source-mac-address | any } {destination
destination-wildcard | host destination | any} {host destination-mac-address | any} [precedence
precedence] [tos tos][fragment] [range lower upper] [ time-range time-range-name ]
When you select the ethernet-type field or cos field:
[sn] deny {[ethernet-type}[cos [out] [inner in]]} [[VID [out][inner in]]] {source source-wildcard | host
source | any} {host source-mac-address | any } {destination destination-wildcard | host destination |
any} {hos
t destination-mac-address | any} [time-range time-range-name]
When you select the protocol field:
[sn] deny protocol [[VID [out][inner in]]] {source source-wildcard | host source | any} {host
source-mac-address | any } {destinationdestination-wildcard | host destination | any} {host
destination-mac-address | any} [precedence precedence] [tos tos] [fragment] [range lower upper]
[time-range time-range-name]
Extended expert ACLs of some important protocols
Internet Control Message Protocol (ICMP)
[sn] deny icmp [[VID [out][inner in]]] {source source-wildcard | host source | any} {host
source-m
ac-address | any} {destination destination-wildcard | host destination | any} {host
destination-mac-address | any} [icmp-type] [[icmp-type [icmp-code ]] | [icmp-message]] [precedence
precedence] [tos tos] [fragment] [time-range time-range-name]
Transmission Control Protocol (TCP)
[sn] deny tcp [[VID [out][inner in]]]{source source-wildcard | host Source | any} {host
source-mac-address | any } [operator port [port]] {destination destination-wildcard | host destination |
any} {host destination-mac-address | any} [operator port [port]] [precedence prec
edence] [tos tos]
[fragment] [range lower upper] [time-range time-range-name] [match-all tcp-flag | established]
User Datagram Protocol (UDP)
[sn] deny udp [[VID [out][inner in]]]{source source –wildcard | host source | any} {host
source-mac-address | any } [ operator port [port]] {destination destination-wildcard | host destination
| any}{host destination-mac-address | any} [operator port [port]] [precedence precedence] [tos tos]
[fragment] [range lower upper] [time-range time-range-name]