ACL comment text management

For ACL-num, enter the number of the ACL.

The comment-textcan be up to 128 characters in length. The comment must be entered separately from the actual ACL entry; that is, you cannot enter the ACL entry and the ACL comment with the same access-listor ip access-listcommand. Also, in order for the remark to be displayed correctly in the output of show commands, the comment must be entered immediately before the ACL entry it describes. Note that an ACL comment is tied to the ACL entry immediately following the comment. Therefore, if the ACL entry is removed, the ACL comment is also removed.

The standard extended parameter indicates the ACL type.

Adding a comment to an entry in a named ACL

To add comments to entries in a named ACL, enter commands such as the following.

Brocade(config)# ip access-list extended TCP/UDP Brocade(config-ext-nACL)# remark The following line permits TCP packets Brocade(config-ext-nACL)# permit tcp 192.168.4.40/24 10.2.2.2/24 Brocade(config-ext-nACL)# remark The following permits UDP packets Brocade(config-ext-nACL)# permit udp 192.168.2.52/24 10.2.2.2/24 Brocade(config-ext-nACL)# deny ip any any

Syntax: [no] access-list standard extended ACL-name

Syntax: remark comment-text

The standard extended parameter indicates the ACL type. For ACL-name, enter the name of the ACL.

The comment-textcan be up to 128 characters in length. The comment must be entered separately from the actual ACL entry; that is, you cannot enter the ACL entry and the ACL comment with the same ip access-listcommand. Also, in order for the remark to be displayed correctly in the output of show commands, the comment must be entered immediately before the ACL entry it describes. Note that an ACL comment is tied to the ACL entry immediately following the comment. Therefore, if the ACL entry is removed, the ACL comment is also removed.

Deleting a comment from an ACL entry

To delete a comment from an ACL entry, enter commands such as the following.

Brocade(config)# ip access-list standard 99

Brocade(config)# no remark The following line permits TCP packets

Syntax: no remark comment-text

Viewing comments in an ACL

You can use the following commands to display comments for ACL entries:

show running-config

show access-list

show ip access-list

Brocade ICX 6650 Security Configuration Guide

103

53-1002601-01

 

Page 123
Image 123
Brocade Communications Systems 6650 Adding a comment to an entry in a named ACL, Deleting a comment from an ACL entry