Extended numbered ACL configuration

gt – The policy applies to TCP or UDP port numbers greater than the port number or the numeric equivalent of the port name you enter after gt.

lt – The policy applies to TCP or UDP port numbers that are less than the port number or the numeric equivalent of the port name you enter after lt.

neq – The policy applies to all TCP or UDP port numbers except the port number or port name you enter after neq.

range – The policy applies to all TCP or UDP port numbers that are between the first TCP or UDP port name or number and the second one you enter following the range parameter. The range includes the port names or numbers you enter. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: range 23 53. The first port number in the range must be lower than the last number in the range.

The tcp/udp-portparameter specifies the TCP or UDP port number or well-known name. You can specify a well-known name for any application port whose number is less than 1024. For other application ports, you must enter the number. Enter “?” instead of a port to list the well-known names recognized by the CLI.

The in out parameter specifies that the ACL applies to incoming traffic on the interface to which you apply the ACL. You can apply the ACL to an Ethernet port or a virtual interface.

NOTE

If the ACL is for a virtual routing interface, you also can specify a subset of ports within the VLAN containing that interface when assigning an ACL to the interface. Refer to “Configuring standard numbered ACLs” on page 86.

The precedence name num parameter of the ip access-listcommand specifies the IP precedence. The precedence option for of an IP packet is set in a three-bit field following the four-bit header-length field of the packet’s header. You can specify one of the following:

critical or 5 – The ACL matches packets that have the critical precedence. If you specify the option number instead of the name, specify number 5.

flash or 3 – The ACL matches packets that have the flash precedence. If you specify the option number instead of the name, specify number 3.

flash-overrideor 4 – The ACL matches packets that have the flash override precedence. If you specify the option number instead of the name, specify number 4.

immediate or 2 – The ACL matches packets that have the immediate precedence. If you specify the option number instead of the name, specify number 2.

internet or 6 – The ACL matches packets that have the internetwork control precedence. If you specify the option number instead of the name, specify number 6.

network or 7 – The ACL matches packets that have the network control precedence. If you specify the option number instead of the name, specify number 7.

priority or 1 – The ACL matches packets that have the priority precedence. If you specify the option number instead of the name, specify number 1.

routine or 0 – The ACL matches packets that have the routine precedence. If you specify the option number instead of the name, specify number 0.

The tos name num parameter of the ip access-listcommand specifies the IP ToS. You can specify one of the following:

max-reliabilityor 2 – The ACL matches packets that have the maximum reliability ToS. The decimal value for this option is 2.

Brocade ICX 6650 Security Configuration Guide

93

53-1002601-01

 

Page 113
Image 113
Brocade Communications Systems manual Brocade ICX 6650 Security Configuration Guide 53-1002601-01