PLANET XGS3-24040 User Manual

Page 443

background image

Chapter 46 ACL Configuration

46-5

(4) Configuring an name-based extended IP access-list

a. Create an extended IP access-list basing on nomenclature

Command

Explanation

Global Mode

ip access-list extended <name>

no ip access-list extended <name>

Creates an extended IP

access-list basing on

nomenclature; the “no ip

access-list extended

“ command deletes

the name-based extended IP

access-list.

b. Specify multiple “permit” or “deny” rules

Command

Explanation

Extended IP ACL Mode

[no] {deny | permit} icmp {{ } |

any-source | {host-source }} {{

} | any-destination | {host-destination

}} [ []]

[precedence ] [tos

][time-range]

Creates an extended

name-based ICMP IP access

rule; the “no” form command

deletes this name-based

extended IP access rule.

[no] {deny | permit} igmp {{ } |

any-source | {host-source }} {{

} | any-destination | {host-destination

}} [] [precedence ] [tos

][time-range]

Creates an extended

name-based IGMP IP access

rule; the “no” form command

deletes this name-based

extended IP access rule.

[no] {deny | permit} tcp {{ } |

any-source | {host-source }} [s-port

{ | range }]

{{ } | any-destination |

{host-destination }} [d-port { |

range }]

[ack+fin+psh+rst+urg+syn] [precedence ] [tos

][time-range]

Creates an extended

name-based TCP IP access

rule; the “no” form command

deletes this name-based

extended IP access rule.

[no] {deny | permit} udp {{ } |

any-source | {host-source }} [s-port

{ | range }]

{{ } | any-destination |

{host-destination }} [d-port { |

range }] [precedence

] [tos ][time-range]

Creates an extended

name-based UDP IP access

rule; the “no” form command

deletes this name-based

extended IP access rule.