COMMAND LINE INTERFACE

Example

This example configures one permit rule for the specific address 10.1.1.21 and another rule for the address range 168.92.16.x – 168.92.31.x using a bitmask.

Console(config-std-acl)#permit host 10.1.1.21 Console(config-std-acl)#permit 168.92.16.0 255.255.240.0 Console(config-std-acl)#

Related Commands

access-list ip (4-118)

permit, deny (Extended ACL)

This command adds a rule to an Extended IP ACL. The rule sets a filter condition for packets with specific source or destination IP addresses, protocol types, source or destination protocol ports, or TCP control codes. Use the no form to remove a rule.

Syntax

[no] {permit deny} [protocol-number udp] {any source address-bitmask host source}

{any destination address-bitmask host destination} [precedence precedence] [tos tos] [dscp dscp]

[source-portsource-port [bitmask]] [destination-portdestination-port [port-bitmask]]

[no] {permit deny} tcp

{any source address-bitmask host source}

{any destination address-bitmask host destination} [precedence precedence] [tos tos] [dscp dscp]

[source-portsource-port [bitmask]] [destination-portdestination-port [port-bitmask]]

[control-flagcontrol-flags flag-bitmask]

protocol-number– A specific protocol number. (Range: 0-255)

source – Source IP address.

destination – Destination IP address.

4-120

Page 364
Image 364
SMC Networks SMC8624/48T manual Access-list ip, No permit deny tcp