beautypg.com

Brocade Mobility RFS7000-GR Controller CLI Reference Guide (Supporting software release 4.1.0.0-040GR and later) User Manual

Page 381

background image

Brocade Mobility RFS7000-GR CLI Reference Guide

367

53-1001945-01

Extended ACL Config Commands

14

Usage Guidelines
Use this command to permit traffic between network’s/host’s based on the protocol type selected
in the access list configuration. The following protocols are supported:

ip

icmp

tcp

udp

The last ACE in the access list is an implict deny statement.

permit {icmp}
{source/source-mask
A.B.C.D/M| host sourcehost
| any} {destination/
destination-maskA.B.C.D/M
| host destinationhosthost |
any}
[icmp-type |
[icmp-type icmp-code]] [log]
[rule-precedence
access-list-entry precedence]

Use with the permit command to allow icmp packets.

permit – The keyword specifies permit action on an ACL.

{icmp} – Specifies icmp as the protocol.

{source/source-mask A.B.C.D/M| host sourcehost | any} – The keyword source
is the source IP address of the network or host in dotted decimal. Source-mask
is the network mask. For example, 10.1.1.10/24 indicates the first 24 bits of
the source IP are used for matching.

any is an abbreviation for source IP of 0.0.0.0 and source-mask bits equal
to 0.

host is an abbreviation for exact source (A.B.C.D) and source-mask bits
equal to 32.

{destination/ destination-maskA.B.C.D/M | host destinationhost | any} – The
destination host IP address or destination network address.

[icmp-type |icmp-type icmp-code] – ICMP type value from 0 to 255. Valid only
for protocol type icmp. ICMP code value from 0 to 255. Valid only for protocol
type icmp.

[log] – Generates log messages when the packet coming from the interface
matches the ACL entry. Log messages are generated only for router ACLs.

[rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.

permit{tcp|udp}
{source/source-mask
A.B.C.D/M| host sourcehost
| any} [operator source-port]
{destination/destination-ma
sk | host destinationhost |
any}
[operator destination-port]
[log]
[rule-precedence
access-list-entry precedence]

Use with the permit command to allow tcp or udp packets.

permit – The keyword specifies permit action on an ACL.

{tcp|udp} – Specify tcp or udp as the protocol.

{source/source-mask A.B.C.D/M| host sourcehost | any} – source is the source
IP address of the network or host in dotted decimal. Source-mask is the
network mask. For example, 10.1.1.10/24 indicates the first 24 bits of the
source IP are used for matching.

any is an abbreviation for source IP of 0.0.0.0 and source-mask bits equal
to 0.

host is an abbreviation for exact source (A.B.C.D) and source-mask bits
equal to 32.

[operator source-port] – Valid only for tcp or udp protocols. Valid values are eq
and range.

range – Specify the protocol range (starting and ending protocol
numbers).

port – Valid Port number.

{destination/destination-mask | host destinationhost | any} – The destination
host IP address or destination network address.

[operator destination-port] – Specify the destination port.

[log] – Generates log messages when the packet coming from the interface
matches the ACL entry. Log messages are generated only for router ACLs.

[rule-precedence access-list-entry precedence] – Integer value between
1-5000. This value sets the rule precedence in the ACL.