access-list (extended) Configuring Access Lists
Enterasys Matrix DFE-Gold Series Configuration Guide 24-19
Defaults
•Ifinsert,replace,ormovearenotspecified,thenewentrywillbeappendedtotheaccesslist.
•Ifsource2isnotspecifiedwithmove,onlyoneentrywillbemoved.
•Ificmptypeandicmpcodearenotspecified,ICMPparameterswillbeappliedtoallICMP
messagetypes.
•If
operatorandportarenotspecified,accessparameterswillbeappliedtoallTCPorUDP
ports.
destinationSpecifiesthenetworkorhosttowhichthepacketwillbesent.Valid
optionsforexpressingdestinationare:
•IPaddress(A.B.C.D)
any‐Anydestinationhost
hostsource‐IPaddressofasingledestinationhost
destination
wildcard
(Optional)Specifiesthebitstoignoreinthedestinationaddress.
icmptype (Optional)FiltersICMPframesbyICMPmessagetype.Thetypeisa
numberfrom0to255.
icmpcode (Optional)FurtherfiltersICMPframesfilteredbyICMPmessagetype
bytheirICMPmessagecode.Thecodeisanumberfrom0to255.
operatorport (Optional)AppliesaccessrulestoTCPorUDPsourceordestination
portnumbers.Possibleoperandsinclude:
ltport‐Matchonlypacketswithalowerportnumber.
gtport‐Matchonlypacketswithagreaterportnumber.
eqport‐Matchonlypacketsonagivenportnumber.
neqport‐Matchonlypacketsnotonagivenportnumber.
rangeminsportmaxsportMatchonlypacketsintherangeof
sourceports
rangemindportmaxdportMatchonlypacketsintherangeof
destinationports.
tosextensions (Optional)Appliesaccessrulestotheprecedenceand/ortosfields,orto
theDiffServfield.Thatis,youcanspecifyoneorbothprecedenceand
tosfields,oryoucanspecifytheDiffServfield.Usethefollowing
keyword/valuepairstospecifythetosextensions:
•precedencevalue(07)‐MatchpacketsbasedontheIPprecedence
value.
tosvalue(015)‐MatchpacketsbasedontheIPTypeofService
value.
dscpvalue(063)‐MatchpacketsbasedontheDiffservcodepoint
value.
established (Optional)AppliesTCPrestrictionstoestablishedconnectionsonly.
log (Optional)Enabletherulebeingconfiguredforsyslog.