Command Reference ACL Commands
Extended IP ACLs of some important protocols:
Internet Control Message Protocol (ICMP)
[ sn ] permit icmp {source source-wildcard | host source | any } { destination destination-wildcard |
host destination | any } [ icmp-type ] [ [ icmp-type [icmp-code ] ] | [ icmp-message ] ] [ precedence
precedence ] [ tos tos ] [ fragment ] [ time-range time-range-name ]
Transmission Control Protocol (TCP)
[ sn ] permit tcp { source source-wildcard | host source | any } [ operator port [ port ] ] { destination
destination-wildcard | host destination | any } [ operator port [ port ] ] [ precedence precedence ]
[ tos tos ] [ fragment ] [ range lower upper ] [ time-range time-range-name ] [
match-all tcp-flag |
established ]
User Datagram Protocol (UDP)
[sn] permit udp {source source -wildcard|host source |any} [ operator port [port]] {destination
destination-wildcard |host destination | any} [operator port [port]] [precedence precedence] [tos
tos] [fragment] [range lower upper] [time-range time-range-name]
Extended MAC ACL
[sn] permit {any | host source-mac-address} {any | host destination-mac-address}
[ethernet-type][ cos [out] [inner in]]
Extended expert ACL
[sn] permit [protoc
ol | [ethernet-type][ cos [out] [inner in]]] [VID [out][inner in]] {source
source-wildcard | host source | any} {host source-mac-address | any } {destination
destination-wildcard | host destination | any} {host destination-mac-address | any} [precedence
precedence] [tos tos][fragment] [range lower upper] [time-range time-range-name]
When you select the Ethernet-type field or cos field:
[sn] permit {ethernet-type| cos [out] [inner in]} [VID [out][inner in]] {source source-wildcard | hos
t
source | any} {host source-mac-address | any } {destination destination-wildcard | host destination
| any} {host destination-mac-address | any} [time-range time-range-name]
When you select the protocol field:
[sn] permit protocol [VID [out][inner in]] {source source-wildcard | host Source | any} {host
source-mac-address | any } {destination destination-wildcard | host destination | any} {host
destination-mac-address | any} [precedence precedence] [tos tos] [fragment] [range lower upper]
[time-range time-range-name]
Extended expert ACLs of some important protocols:
Internet Control Message Protocol (ICMP)
[sn] permit icmp [VID [out][i
nner in]] {source source-wildcard | host source | any} {host
source-mac-address | any } {destination destination-wildcard | host destination | any} {host
destination-mac-address | any}[ icmp-type ] [[icmp-type [icmp-code ]] | [ icmp-message ]]
[precedence precedence] [tos tos] [fragment] [time-range time-range-name]
Transmission Control Protocol (TCP)
[sn] permit tcp [VID [out][inner in]]{source source-wildcard | host Source | any} {host
source-mac-address | any } [operator port [port]] {destination destination-wildcard | host destinati
on |
any} {host destination-mac-address | any} [operator port [port]] [precedence precedence] [tos tos]
[fragment] [range lower upper] [time-range time-range-name] [match-all tcp-flag | established]
User Datagram Protocol (UDP)
[sn] permit udp [VID [out][inner in]]{source source –wildcard | host source | any} {host