ES4710BD 10 Slots L2/L3/L4 Chassis Switch

[no] {deny permit} tcp {{<sIpAddr> <sMask>}

 

any-source {host-source <sIpAddr>}} [s-port

Creates an extended name-based

<sPort>] {{<dIpAddr> <dMask>} any-destination

TCP IP access rule; the “no” form

{host-destination <dIpAddr>}} [d-port <dPort>]

command deletes this name-based

[ack fin psh rst syn urg] [precedence <prec>]

extended IP access rule

[tos <tos>]

 

[no] {deny permit} udp {{<sIpAddr> <sMask>}

Creates an extended name-based

any-source {host-source <sIpAddr>}} [s-port

UDP IP access rule; the “no” form

<sPort>] {{<dIpAddr> <dMask>} any-destination

command deletes this name-based

{host-destination <dIpAddr>}} [d-port <dPort>]

extended IP access rule

[precedence <prec>] [tos <tos>]

 

[no] {deny permit} {eigrp gre igrp ipinip ip

Creates an extended name-based IP

<int>} {{<sIpAddr> <sMask>} any-source

access rule for other IP protocols;

{host-source<sIpAddr>}} {{<dIpAddr> <dMask>}

the “no” form command deletes

any-destination {host-destination <dIpAddr>}}

this name-based extended IP access

[precedence <prec>] [tos <tos>]

rule

c.Exit extended IP ACL configuration mode

Command

 

Explanation

Extended IP

ACL Mode

 

Exit

 

Exits extended name-based IP ACL configuration

 

mode

 

 

2.Configuring packet filtering function

(1) Enable global packet filtering function

 

Command

Explanation

 

Global Mode

 

 

Firewall enable

Enables global packet filtering function

 

Firewall disable

disables global packet filtering function

(2) Configure default action.

 

 

Command

Explanation

 

Global Mode

 

 

Firewall default permit

Sets default action to “permit”

 

Firewall default deny

Sets default action to “deny”

3.Bind access-list to a specific direction of the specified port.

Command

Explanation

Physical Interface Mode

 

270

Page 271
Image 271
Accton Technology ES4710BD manual Host-source sIpAddr dIpAddr dMask