6 access-list(mac-ip extended), Access, List – PLANET XGS3-24042 User Manual

Page 942: Ip extended

Advertising
background image

47-8

No access-list configured

Usage Guide:

When the user assign specific <num> for the first time, ACL of the serial number is created, then the

lists are added into this ACL.

Examples:

Permit tagged-eth2 with any source MAC addresses and any destination MAC addresses and the

packets whose 17th and 18th byte is 0x08, 0x0 to pass.

Switch(config)#access-list 1100 permit any-source-mac any-destination-mac tagged-eth2 16 2

0800

47.6 access-list(mac-ip extended)

Command:

access-list<num>{deny|permit}{any-source-mac|

{host-source-mac<host_smac>}|{<smac><smac-mask>}}

{any-destination-mac|{host-destination-mac <host_dmac>}|{<dmac><dmac-mask>}}icmp

{{<source><source-wildcard>}|any-source|{host-source<source-host-ip>}}

{{<destination><destination-wildcard>}|any-destination|

{host-destination<destination-host-ip>}}[<icmp-type> [<icmp-code>]] [precedence

<precedence>] [tos <tos>][time-range<time-range-name>]

access-list<num>{deny|permit}{any-source-mac|

{host-source-mac<host_smac>}|{<smac><smac-mask>}}

{any-destination-mac|{host-destination-mac <host_dmac>}|{<dmac><dmac-mask>}}igmp

{{<source><source-wildcard>}|any-source|{host-source<source-host-ip>}}

{{<destination><destination-wildcard>}|any-destination|

{host-destination<destination-host-ip>}} [<igmp-type>] [precedence <precedence>] [tos

<tos>][time-range<time-range-name>]

access-list <num> {deny|permit}{any-source-mac| {host-source-mac

<host_smac> }|{ <smac> <smac-mask> }}{any-destination-mac| {host-destination-mac

<host_dmac> }|{ <dmac> <dmac-mask> }}tcp {{ <source> <source-wildcard> }|any-source|

{host-source <source-host-ip> }}[s-port{ <port1> | range <sPortMin> <sPortMax> }]

{{ <destination> <destination-wildcard> } | any-destination | {host-destination

<destination-host-ip> }} [d-port { <port3> | range <dPortMin> <dPortMax> }]

[ack+fin+psh+rst+urg+syn] [precedence <precedence> ] [tos <tos> ] [time-range

<time-range-name> ]

access-list <num> {deny|permit}{any-source-mac| {host-source-mac

<host_smac> }|{ <smac> <smac-mask> }}{any-destination-mac| {host-destination-mac

Advertising
This manual is related to the following products: