Security and authentication
11.4 IP access control list
SCALANCE XM-400/XR-500 Command Line Interface (CLI)
842 Configuration Manual, 06/2016, C79000-G8976-C252-11
Note
Processing order of the lists
The access control lists are processed on the interface in the order in which they were
created.
The index number of the access control list is
not used for this.
You are in the ACL standard configuration mode.
The command prompt is as follows:
cli(config-std-nacl)#
Call up the command with the following parameters:
deny {any | ospf | vrrp | <protocol-type type(1-255)>} {any | host <src-ip> |
<network-src-ip> <mask>} {any | host <dest-ip> | <network-dest-ip> <mask>} [dscp
<value(0-63)>]
or
deny {any | host <src-ip> | <network-src-ip> <mask>} [ { any | host <dest-ip> |
<network-dest-ip> <mask>}]
The parameters have the following meaning:
Keyword for the protocol type
Blocks all incoming frames
Keyword for a single IP address
Enter a valid IP address.
Enter a valid combination of IP
address and subnet mask.
Corresponding subnet mask
Blocks all outgoing frames
Keyword for a single IP address
Enter a valid IP address.
Network destination address Enter a valid combination of IP
address and subnet mask.
Corresponding subnet mask
Value 0 ... 63