beautypg.com

Access control lists, Ipv4 acls, Chapter 11 – Brocade 6910 Ethernet Access Switch Configuration Guide (Supporting R2.2.0.0) User Manual

Page 289: Table 57, Table 58, Chapter

background image

Brocade 6910 Ethernet Access Switch Configuration Guide

233

53-1002651-02

Chapter

11

Access Control Lists

In this chapter

Access Control Lists (ACL) provide packet filtering for IPv4 frames (based on address, protocol,
Layer 4 protocol port number or TCP control code), IPv6 frames (based on address, DSCP traffic
class, or next header type), or any frames (based on MAC address or Ethernet type). To filter
packets, first create an access list, add the required rules, and then bind the list to a specific port.
This section describes the Access Control List commands.

IPv4 ACLs

The commands in this section configure ACLs based on IPv4 addresses, TCP/UDP port number,
protocol type, and TCP control code. To configure IPv4 ACLs, first create an access list containing
the required permit or deny rules, and then bind the access list to one or more ports.

TABLE 57

Access Control List Commands

Command Group

Function

IPv4 ACLs

Configures ACLs based on IPv4 addresses, TCP/UDP port number, protocol type,
and TCP control code

IPv6 ACLs

Configures ACLs based on IPv6 addresses, DSCP traffic class, or next header type

MAC ACLs

Configures ACLs based on hardware addresses, packet format, and Ethernet type

ARP ACLs

Configures ACLs based on ARP messages addresses

ACL Information

Displays ACLs and associated rules; shows ACLs assigned to each port

TABLE 58

IPv4 ACL Commands

Command

Function

Mode

access-list ip

Creates an IP ACL and enters configuration mode for standard or
extended IPv4 ACLs

GC

permit, deny

Filters packets matching a specified source IPv4 address

IPv4-STD-ACL

permit, deny

Filters packets meeting the specified criteria, including source
and destination IPv4 address, TCP/UDP port number, protocol
type, and TCP control code

IPv4-EXT-ACL

ip access-group

Binds an IPv4 ACL to a port

IC

show ip access-group

Shows port assignments for IPv4 ACLs

PE

show ip access-list

Displays the rules for configured IPv4 ACLs

PE