PLANET XGS3-24042 User Manual

Page 939

Advertising
background image

47-5

access-list <num> {deny | permit} udp {{ <sIpAddr> <sMask> } | any-source | {host-source

<sIpAddr> }} [s-port { <sPort> | range <sPortMin> <sPortMax> ] {{ <dIpAddr> <dMask> } |

any-destination | {host-destination <dIpAddr> }} [d-port { <dPort> | range <dPortMin>

<dPortMax> }] [precedence <prec> ] [tos <tos> ][time-range<time-range-name> ]

access-list <num> {deny | permit} {eigrp | gre | igrp | ipinip | ip | ospf | <protocol-num> }

{{ <sIpAddr> <sMask> } | any-source | {host-source <sIpAddr> }} {{ <dIpAddr> <dMask> } |

any-destination | {host-destination <dIpAddr> }} [precedence <prec> ] [tos

<tos> ][time-range <time-range-name> ]

no access-list <num>

Functions:

Create a numeric extended IP access rule to match specific IP protocol or all IP protocol; if

access-list of this coded numeric extended does not exist, thus to create such a access-list.

Parameters:

<num> is the No. of access-list, 100-299; <protocol> is the No. of upper-layer protocol of ip, 0-255;

<sIpAddr> is the source IP address, the format is dotted decimal notation; <sMask > is the reverse

mask of source IP, the format is dotted decimal notation; <dIpAddr> is the destination IP address,

the format is dotted decimal notation; <dMask> is the reverse mask of destination IP, the format is

dotted decimal notation, attentive position o, ignored position1;<igmp-type>,the type of igmp, 0-15;

<icmp-type>, the type of icmp, 0-255;<icmp-code>, protocol No. of icmp, 0-255;<prec>, IP priority,

0-7; <tos>, to value, 0-15; <sPort>, source port No., 0-65535; <sPortMin>, the down boundary of

source port; <sPortMax>, the up boundary of source port; <dPortMin>, the down boundary of

destination port; <dPortMax>, the up boundary of destination port; <dPort>, destination port No.,

0-65535; <time-range-name>, the name of time-range.

Command Mode:

Global mode

Default:

No access-lists configured.

Usage Guide:

When the user assign specific <num> for the first time, ACL of the serial number is created, then

the lists are added into this ACL; the access list which marked 200-299 can configure not continual

reverse mask of IP address.

<igmp-type> represent the type of IGMP packet, and usual values please refer to the following

description:

17(0x11): IGMP QUERY packet

18(0x12): IGMP V1 REPORT packet

22(0x16): IGMP V2 REPORT packet

23(0x17): IGMP V2 LEAVE packet

34(0x22): IGMP V3 REPORT packet

Advertising
This manual is related to the following products: