Chapter2ACLConguration
Related
Commands
deny
permit(ExtendedFormat)
PurposeUsethiscommandtocongurethepermitconditionsforanex-
tendedIPaccesslist.Removethepermitconditionswiththeno
formofthiscommand.
CommandModesExtendedACLconguration
Syntaxpermit<protocol><source><source-wildcard>[<source-port
>]<destination><destination-wildcard>[<destination-port>][ti
me-range<timerange-name>][log]
nopermit<protocol><source><source-wildcard>[<source-por
t>]<destination><destination-wildcard>[<destination-port>][ti
me-range<timerange-name>][log]
Syntax
Description
<protocol>Protocoltypetobematched,ICMP ,IP ,TCPor
UDP;anintegerstandingfortheIPprotocol
number ,range:0~254
<source>
SourceIPaddresstobematched,indotted
decimalformat
<source-wildcard>Wildcardshieldingcodematchedthesource,
indotteddecimalformat
<source-port>
Sourceport
<destination>DestinationIPaddresstobematched,in
dotteddecimalformat
<destination-wildca
rd>
Wildcardshieldingcodematchedthe
destination,indotteddecimalformat
<destination-port>
Destinationport
time-range
<timerange-name>
Timerangename,thelengthisnotmorethan
31characters
logLogstheIPpacketsthatmeetthisrule
(availableforZXR10GAR,ZXR10ZSRonly)
ExampleThisexampledescribeshowtoallowaccessingtoahostonthe
speciednetwork
ZXR10(config)#aclextendednumber100
ZXR10(config-ext-acl)#permiticmp
10.2.3.00.0.0.25520.5.0.00.0.255.2558
ZXR10(config-ext-acl)#permittcp168.1.1.00.0.0.255
le300168.5.6.00.0.0.255ge200established
ZXR10(config-ext-acl)#permiticmp
126.1.1.00.0.0.25510.5.0.00.0.255.255log
CondentialandProprietaryInformationofZTECORPORATION23