Table 10: Acl Command Parameters - D-Link DWS-4000 Series Cli Command Reference

Hide thumbs Also See for DWS-4000 Series:
Table of Contents

Advertisement

IP Standard ACL:
Format
access-list <1-99> {deny | permit} {every | <srcip> <srcmask>} [log] [assign-
queue <queue-id>] [mirror <slot/port>]
Mode
Global Config
IP Extended ACL:
Format
access-list <100-199> {deny | permit} {every | {{icmp | igmp | ip | tcp | udp
| <number>} <srcip> <srcmask>[{eq {<portkey> | <0-65535>} <dstip> <dstmask>
[{eq {<portkey>| <0-65535>}] [precedence <precedence> | tos <tos> <tosmask> |
dscp <dscp>] [log] [assign-queue <queue-id>] [mirror <slot/port>]
Mode
Global Config
Parameter
<1-99> or <100-199>
{deny | permit}
every
{icmp | igmp | ip | tcp | udp |
<number>}
<srcip> <srcmask>
[{eq {<portkey> |
<0-65535>}]
<dstip> <dstmask>
[precedence <precedence> | tos
<tos> <tosmask> | dscp <dscp>]
[log]
[assign-queue <queue-id>]
[mirror <slot/port>]
no access-list
This command deletes an IP ACL that is identified by the parameter <accesslistnumber> from the system. The range
for <accesslistnumber> 1-99 for standard access lists and 100-199 for extended access lists.
Format
no access-list <accesslistnumber>
Mode
Global Config

Table 10: ACL Command Parameters

Description
Range 1 to 99 is the access list number for an IP standard ACL. Range 100 to
199 is the access list number for an IP extended ACL.
Specifies whether the IP ACL rule permits or denies an action.
Note: Assign-queue and mirror attributes are configurable for a deny rule,
but they have no operational effect.
Match every packet.
Specifies the protocol to filter for an extended IP ACL rule.
Specifies a source IP address and source netmask for match condition of the
IP ACL rule.
Specifies the source layer 4 port match condition for the IP ACL rule. You can
use the port number, which ranges from 0-65535, or you specify the
<portkey>, which can be one of the following keywords: domain, echo,
ftp, ftpdata, http, smtp, snmp, telnet, tftp, and www. Each of
these keywords translates into its equivalent port number, which is used as
both the start and end of a port range.
Specifies a destination IP address and netmask for match condition of the IP
ACL rule.
Specifies the TOS for an IP ACL rule depending on a match of precedence or
DSCP values using the parameters dscp , precedence, tos/tosmask.
Specifies that this rule is to be logged.
Specifies the assign-queue, which is the queue identifier to which packets
matching this rule are assigned.
Specifies the mirror interface which is the slot/port to which packets matching
this rule are copied.
IP Access Control List Commands
401

Advertisement

Table of Contents
loading

This manual is also suitable for:

Dwl-8600ap

Table of Contents