4 Command Line Interface

Table 4-32. Access Control Lists

Command Groups

Function

Page

IP ACLs

Configures ACLs based on IP addresses, TCP/UDP port number,

4-86

 

protocol type, and TCP control code

 

MAC ACLs

Configures ACLs based on hardware addresses, packet format, and

4-93

 

Ethernet type

 

ACL Information

Displays ACLs and associated rules; shows ACLs assigned to each port

4-98

 

 

 

IP ACLs

Table 4-33. IP ACLs

Command

Function

Mode

Page

access-list ip

Creates an IP ACL and enters configuration mode

GC

4-86

 

 

 

 

permit, deny

Filters packets matching a specified source IP address

STD-ACL

4-87

 

 

 

 

permit, deny

Filters packets meeting the specified criteria, including

EXT-ACL

4-88

 

source and destination IP address, TCP/UDP port number,

 

 

 

protocol type, and TCP control code

 

 

show ip access-list

Displays the rules for configured IP ACLs

PE

4-90

 

 

 

 

ip access-group

Adds a port to an IP ACL

IC

4-90

 

 

 

 

show ip access-group

Shows port assignments for IP ACLs

PE

4-90

 

 

 

 

map access-list ip

Sets the CoS value and corresponding output queue for

IC

4-91

 

packets matching an ACL rule

 

 

show map access-list ip

Shows CoS value mapped to an access list for an interface

PE

4-92

 

 

 

 

access-list ip

This command adds an IP access list and enters configuration mode for standard or extended IP ACLs. Use the no form to remove the specified ACL.

Syntax

[no] access-list ip {standard extended} acl_name

standard – Specifies an ACL that filters packets based on the source IP address.

extended – Specifies an ACL that filters packets based on the source or destination IP address, and other more specific criteria.

acl_name – Name of the ACL. (Maximum length: 16 characters)

Default Setting

None

Command Mode

Global Configuration

4-86

Page 262
Image 262
SMC Networks 100BASE-TX, 16 10BASE-T manual IP ACLs, Access-list ip, Access Control Lists Command Groups Function