beautypg.com

PLANET XGS3-24042 User Manual

Page 953

background image

47-19

{{ } | any-destination | {host-destination }} []

[precedence ] [tos ][time-range]

[no] {deny | permit} tcp {{ } | any-source | {host-source }}

[s-port { | range }] {{ } | any-destination

| {host-destination <dIpAddr> }} [d-port { | range <dPortMax> }]

[ack+fin+psh+rst+urg+syn] [precedence ] [tos ][time-range

]

[no] {deny | permit} udp {{ } | any-source | {host-source }}

[s-port { > | range > }] {{ } | any-destination

| {host-destination }} [d-port { <dPort> | range <dPortMax> }]

[precedence ] [tos ][time-range ]

[no] {deny | permit} {eigrp | gre | igrp | ipinip | ip | ospf | <protocol-num>} {{

} | any-source | {host-source }} {{ } | any-destination |

{host-destination }} [precedence ] [tos

][time-range]

Functions:

Create a name extended IP access rule to match specific IP protocol or all IP protocol.

Parameters:

is the source IP address, the format is dotted decimal notation; <sMask > is the reverse

mask of source IP, the format is dotted decimal notation; is the destination IP address,

the format is dotted decimal notation; <dMask> is the reverse mask of destination IP, the format is

dotted decimal notation, attentive position o, ignored position 1; <igmp-type>, the type of igmp,

0-15; , the type of icmp, 0-255 ; , protocol No. of icmp, 0-255; , IP

priority, 0-7; , to value, 0-15; , source port No., 0-65535; , the down

boundary of source port; , the up boundary of source port; , destination port

No. 0-65535; , the down boundary of destination port; , the up boundary of

destination port; , time range name.

Command Mode:

Name extended IP access-list configuration mode

Default:

No access-list configured.

Examples:

Create the extended access-list, deny icmp packet to pass, and permit udp packet with destination

address 192. 168. 0. 1 and destination port 32 to pass.

Switch(config)# access-list ip extended udpFlow

Switch(Config-IP-Ext-Nacl-udpFlow)#deny igmp any any-destination

Switch(Config-IP-Ext-Nacl-udpFlow)#permit udp any host-destination 192.168.0.1 d-port 32

This manual is related to the following products: