17 mac-ip access extended, 18 permit | deny (ip extended), Ip access extended – PLANET WGSW-50040 User Manual

Page 328: Permit, Deny, Ip extended

Advertising
background image

Commands for Security Function Chapter 6 Commands for TACACS+

21.17 mac-ip access extended

Command:

mac-ip-access-list extended <name>

no mac-ip-access-list extended <name>

Functions:

Define a name-manner MAC-IP ACL or enter access-list configuration mode, “no

mac-ip-access-list extended <name>” command deletes this ACL.

Parameters:

<name>: name of access-list excluding blank or quotation mark, and it must start with letter, and the

length cannot exceed 16 (remark: sensitivity on capital or small letter).

Command Mode:

Global Mode.

Default:

No named MAC-IP access-list.

Usage Guide:

After assigning this commands for the first time, only an empty name access-list is created and no

list item included.

Examples:

Create an MAC-IP ACL named macip_acl.

Switch(config)# mac-ip-access-list extended macip_acl

Switch(Config-MacIp-Ext-Nacl-macip_acl)#

21.18 permit | deny (ip extended)

Command:

[no] {deny | permit} icmp {{<sIpAddr> <sMask>} | any-source | {host-source <sIpAddr>}}

{{<dIpAddr> <dMask>} | any-destination | {host-destination <dIpAddr>}} [<icmp-type>

[<icmp-code>]] [precedence <prec>] [tos <tos>][time-range<time-range-name>]

[no] {deny | permit} igmp {{<sIpAddr> <sMask>} | any-source | {host-source <sIpAddr>}}

{{<dIpAddr> <dMask>} | any-destination | {host-destination <dIpAddr>}} [<igmp-type>]

[precedence <prec>] [tos <tos>][time-range<time-range-name>]

[no] {deny | permit} tcp {{ <sIpAddr> <sMask> } | any-source | {host-source <sIpAddr> }}

[s-port { <sPort> | range <sPortMin> <sPortMax> }] {{ <dIpAddr> <dMask> } | any-destination

| {host-destination <dIpAddr> }} [d-port { <dPort> | range <dPortMin> <dPortMax> }]

[ack+fin+psh+rst+urg+syn] [precedence <prec> ] [tos <tos> ][time-range

<time-range-name> ]

Advertising