Patton electronic 2800 user manual Where the syntax is, Src-wildcard

Models: 2800

1 135
Download 135 pages 34.01 Kb
Page 84
Image 84

OnSite 2800 Series User Manual7 • Access control list configuration

Mode: Profile access control list

Step

Command

Purpose

 

 

 

1node(pf-acl)[name]#deny ip {src src-wildcard any host Creates an IP access of control list

src} {dest dest-wildcard any host dest} [cos group]

entry that denies access defined

 

according to the command

 

options

Where the syntax is:

Keyword

Meaning

 

 

src

The source address to be included in the rule. An IP address in dotted-decimal-format,

 

e.g. 64.231.1.10.

src-wildcard

A wildcard for the source address. Expressed in dotted-decimal format this value specifies

 

which bits are significant for matching. One-bits in the wildcard indicate that the corre-

 

sponding bits are ignored. An example for a valid wildcard is 0.0.0.255, which speci-

 

fies a class C network.

 

 

any

Indicates that IP traffic to or from all IP addresses is to be included in the rule.

host src

The address of a single source host.

 

 

dest

The destination address to be included in the rule. An IP address in dotted-decimal-for-

 

mat, e.g. 64.231.1.10.

dest-wildcard

A wildcard for the destination address. See src-wildcard

 

 

host dest

The address of a single destination host.

cos

Optional. Specifies that packets matched by this rule belong to a certain Class of Service

 

(CoS). For detailed description of CoS configuration refer to chapter 8, “Link scheduler

 

configuration” on page 93.

 

 

group

CoS group name.

 

 

If you place a deny ip any any rule at the top of an access control list profile, no packets will pass regardless of the other rules you defined.

Example: Create IP access control list entries

Select the access-list profile named WanRx and create some filter rules for it.

2800(cfg)#profile acl WanRx

2800(pf-acl)[WanRx]#permit ip host 62.1.2.3 host 193.14.2.11 cos Urgent 2800(pf-acl)[WanRx]#permit ip 62.1.2.3 0.0.255.255 host 193.14.2.11 2800(pf-acl)[WanRx]#permit ip 97.123.111.0 0.0.0.255 host 193.14.2.11 2800(pf-acl)[WanRx]#deny ip any any

2800(pf-acl)[WanRx]#exit 2800(cfg)#

Access control list configuration task list

84

Page 84
Image 84
Patton electronic 2800 user manual Where the syntax is, Src-wildcard