1414 Management ACL Commands
deny (management)
Use the deny command in Management Access-List Configuration mode to
set conditions for the management access list.
Syntax
deny [gigabitethernet
unit/slot/port
| vlan
vlan-id
|
port-channel
port-
channel-number
| tengigabitethernet
unit/slot/port
] [service

service

] [priority
priority
]
deny ip-source
ip-address
[mask
mask
|
prefix-length
] [gigabitethernet
unit/slot/port
| vlan
vlan-id
|
port-channel
port-channel-number
|
tengigabitethernet
unit/slot/port
] [service

service

] [priority
priority
]
gigabitethernet
unit/slot/port
— A valid 1-gigabit Ethernet-routed port
number.
vlan
vlan-id
— A valid VLAN number.
port-channel
port-channel-number
— A valid routed port-channel
number.
tengigabitethernet
unit/slot/port
— A valid 10-gigabit Ethernet-routed
port number.
ip-address
— Source IP address.
mask

mask

— Specifies the network mask of the source IP address.
mask
prefix-length
— Specifies the number of bits that comprise the
source IP address prefix. The prefix length must be preceded by a forward
slash (/). (Range: 0–32)
service

service

— Indicates service type. Can be one of the following:
telnet
,
ssh
,
http
,
https
,
tftp
,
snmp
,
sntp
, or
any
. The
any
keyword indicates
that the service match for the ACL is effectively "don’t care".

priority

priority

— Priority for the rule. (Range: 1–64)
Default Configuration
This command has no default configuration.
Command Mode
Management Access-list Configuration mode
2CSPC4.XCT-SWUM2XX1.book Page 1414 Monday, October 3, 2011 11:05 AM