SMC Networks SMC6724L3 manual Ip access-group

Models: SMC6724L3

1 618
Download 618 pages 36.53 Kb
Page 367
Image 367

ACCESS CONTROL LIST COMMANDS

-Both SYN and ACK valid, use “control-code 18 18”

-SYN valid and ACK invalid, use “control-code 2 18”

Example

This example accepts any incoming packets if the source address is within subnet 10.7.1.x. For example, if the rule is matched; i.e., the rule (10.7.1.0

&255.255.255.0) equals the masked address (10.7.1.2 & 255.255.255.0), the packet passes through.

Console(config-ext-acl)#permit 10.7.1.1 255.255.255.0 any Console(config-ext-acl)#

This allows TCP packets from class C addresses 192.168.1.0 to any destination address when set for destination TCP port 80 (i.e., HTTP).

Console(config-ext-acl)#permit 192.168.1.0 255.255.255.0 any dport 80

Console(config-ext-acl)#

This permits all TCP packets from class C addresses 192.168.1.0 with the TCP control code set to “SYN.”

Console(config-ext-acl)#permit 192.168.1.0 255.255.255.0 any tcp control-code 2 2

Console(config-ext-acl)#

Related Commands

access-list ip (4-76)

ip access-group

Use this command to bind a port to an IP ACL. Use the no form to remove the port.

Syntax

ip access-group acl_name in no ip access-group acl_name in

acl_name – Name of the ACL. (Maximum length: 16 characters)

in – Indicates that this list applies to input packets.

4-81

Page 367
Image 367
SMC Networks SMC6724L3 manual Syntax Ip access-group aclname in no ip access-group aclname