Brocade-communications-systems RFS6000 Manual de usuario Pagina 454

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 839
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 453
452 Brocade Mobility RFS4000, RFS6000 and RFS7000 CLI Reference Guide
53-1001931-01
Extended ACL config commands
14
Parameters
deny ip
[<source-IP/Mask>|any|ho
st
<IP>][<dest-IP/Mask>|any|
host <IP>] {log}
{rule-precedence
<1-5000>}
Use with a deny command to reject IP packets
deny – Sets the action type on an ACL
ip – Specifies an IP (to match to a protocol)
<source-ip/mask>|any|host <IP> – The keyword
<source-IP> is the source IP address of the network or host
in dotted decimal format. The <Mask> is the network mask.
For example, 10.1.1.10/24 indicates the first 24 bits of the
source IP is used for matching.
any – any is an abbreviation for a source IP of 0.0.0.0 and
source-mask bits equal to 0
hosthost is an abbreviation for the exact source <ip>
(A.B.C.D format) and source-mask bits equal to 32
<dest-IP/Mask>|any|host <IP> – Defines the destination
host IP address or destination network address.
log – Generates log messages when the packet coming from
the interface matches an ACL entry. Log messages are
generated only for router ACLs.
rule-precedence <1-5000> – Defines an integer value
between 1-5000. This value sets the rule precedence in the
ACL.
deny icmp
[<source-IP/Mask>|any|ho
st <IP>]
[<dest-IP/Mask>|any|host
<IP>] {<ICMP-type>
{<ICMP-code>}} {log}
{rule-precedence
<1-5000>}
Use with the deny command to reject ICMP packets
deny – Rejects ICMP packets
icmp – Specifies ICMP as the protocol
[<source-ip/mask>|any|host <IP>] – The source
<source-IP> is the source IP address of the network or host
(in dotted decimal format). The <mask> is the network mask.
For example, 10.1.1.10/24 indicates the first 24 bits of the
source IP is used for matching.
any – any is an abbreviation for a source IP of 0.0.0.0 and
source-mask bits equal to 0
host – host is an abbreviation for exact source (A.B.C.D) and
source-mask bits equal to 32
[<dest-IP/Mask>|any|host <IP>] – Defines the destination
host IP address or destination network address
<ICMP-type> {<ICMP-code>} Sets the ICMP type value
<ICMP-type> from 0 to 255, and is valid only for ICMP. The
ICMP code value <ICMP-code> is from 0 to 255, and is valid
only for protocol type icmp.
log – Generates log messages when the packet coming from
the interface matches the ACL entry. Log messages are
generated only for router ACLs.
rule-precedence <1-5000> – Optional. Defines an integer
value between 1-5000. This value sets the rule precedence
in the ACL.
Vista de pagina 453
1 2 ... 449 450 451 452 453 454 455 456 457 458 459 ... 838 839

Comentarios a estos manuales

Sin comentarios