Named acl, Other acl commands, Named acl other acl commands – Brocade BigIron RX Series Configuration Guide User Manual
Page 1498

1420
BigIron RX Series Configuration Guide
53-1002484-04
ACLs (IP)
E
Named ACL
Other ACL commands
Commands
See ...
ip access-list extended I standard
<
acl-name>
“Named ACLs: adding a comment to a new ACL”
ip access-list extended
<
string> |
<
num> deny | permit
<
ip-protocol>
<
source-ip> |
<
hostname>
<
wildcard>
[
<
operator>
<
source-tcp/udp-port>]
<
destination-ip> |
<
hostname>
<
wildcard> [
<
operator>
<
destination-tcp/udp-port>] [match-all
<
tcp-flags>]
[match-any
<
tcp-flags>] [
<
icmp-type>] [established]
[precedence
<
name> |
<
num>] [tos
<
number>]
[dscp-matching
<
number>] [802.1p-priority-matching
<
number>] [dscp-marking
<
number>
802.1p-priority-marking
<
number>
internal-priority-marking
<
number>] [dscp-marking
<
number> dscp-cos-mapping] [dscp-cos-mapping]
[fragment] [non-fragment] [first-fragment] [fragment-offset
<
number>] [spi
<
00000000 - ffffffff>] [log]
“Configuring standard or extended named ACLs”
“Enabling ACL filtering of fragmented or
non-fragmented packets”
ip access-list extended
<
string> I
<
num> deny | permit
host
<
ip-protocol>
any any [log]
ip access-list extended
<
acl-name>
deny | permit host icmp any any [log]
<
icmp-type> |
<
type-number>
<
code-number>
“ICMP filtering for extended ACLs”
ip access-list standard
<
string> deny | permit
<
source-ip> |
<
hostname>
<
wildcard> [log]
“Configuring standard or extended named ACLs”
ip access-list standard
<
string> deny | permit
<
source-ip>/
<
mask-bits> |
<
hostname> [log]
ip access-list standard
<
string> deny | permit any [log]
ip access-list standard
<
string> deny | permit host
<
source-ip> |
<
hostname> [log]
no
<
entire-deny-or-permit-statement>
remark
<
string>
“Named ACLs: adding a comment to a new ACL”
“Named ACLs: deleting a comment”
show access-list name
<
acl-name>
Commands
See ...
acl-duplication-check
“Enabling ACL duplication check”
clear access-list all | ethernet
<
slot>/
<
port> | ve
<
ve-num>