EX2500 Ethernet Switch Configuration Guide

IP Extended ACLs

The switch supports up to 128 IP ACLs (standard and extended), numbered from

128 through 254. Use IP Extended ACLs to filter traffic using the following criteria:

„Source IP address or network mask

„Destination IP address or network mask

„IP protocol number or name as shown in Table 12

„TCP/UDP application ports, as shown in Table 13 on page 55

„TCP flags

„ICMP message code and type

„Type of Service (ToS) value

„DSCP value

To create an IP Extended ACL:

ex2500(config)# access-list ip 128 extended ex2500(config-ext-nacl)#

To delete an IP Extended ACL:

ex2500(config)# no access-list ip 128 extended ex2500(config)#

Table 12: Well-Known Protocol Types

Number Protocol Name

1 icmp

4 ip

6 tcp

17 udp

89ospf

103pim

54„ Using ACL Filters

Page 68
Image 68
Juniper Networks EX2500 manual IP Extended ACLs, To delete an IP Extended ACL