COMMAND LINE INTERFACE

Command

Function

Page

Groups

 

 

 

 

 

IP ACLs

Configures ACLs based on IP addresses, TCP/UDP

4-76

 

port number, protocol type, and TCP control code

 

 

 

 

MAC ACLs

Configures ACLs based on hardware addresses,

4-84

 

packet format, and Ethernet type

 

 

 

 

ACL Information

Displays ACLs and associated rules; shows ACLs

4-89

 

assigned to each port

 

 

 

 

IP ACLs

Command

Function

Mode

Page

access-list ip

Creates an IP ACL and enters configuration

GC

4-76

 

mode

 

 

 

 

 

 

permit, deny

Filters packets matching a specified source IP

STD-

4-78

 

address

ACL

 

 

 

 

 

permit, deny

Filters packets meeting the specified criteria,

EXT-

4-79

 

including source and destination IP address,

ACL

 

 

TCP/UDP port number, protocol type, and

 

 

 

TCP control code

 

 

 

 

 

 

ip access-group

Adds a port to an IP ACL

IC

4-81

 

 

 

 

show ip

Shows port assignments for IP ACLs

PE

4-81

access-group

 

 

 

 

 

 

 

show ip access-list

Displays the rules for configured IP ACLs

PE

4-83

 

 

 

 

access-list ip

Use this command to add an IP access list and enter configuration mode for standard or extended IP ACLs. Use the no form to remove the specified ACL.

Syntax

access-list ip {standard extended} acl_name no access-list ip {standard extended} acl_name

standard – Specifies an ACL that filters packets based on the source IP address.

4-76

Page 362
Image 362
SMC Networks SMC6724L3 manual IP ACLs, Access-list ip