Qtech QSW-8200-52T-POEAC- DC Команды для функции безопасности онлайн [11/114] 481625

Qtech QSW-8200-52T-POEAC- DC Команды для функции безопасности онлайн [11/114] 481625
User Manual
Chapter 1. Commands for ACL 11
www.qtech.ru
access-list <num> {deny | permit} tcp {{ <sIpAddr> <sMask> } | any-source | {host-
source <sIpAddr> }} [s-port { <sPort> | range <sPortMin> <sPortMax> }] {{ <dIpAddr>
<dMask> } | any-destination | {host-destination <dIpAddr> }} [d-port { <dPort> |
range <dPortMin> <dPortMax> }] [ack+ fin+ psh+ rst+ urg+ syn] [precedence <prec> ]
[tos <tos> ][time-range <time-range-name> ]
access-list <num> {deny | permit} udp {{ <sIpAddr> <sMask> } | any-source | {host-
source <sIpAddr> }} [s-port { <sPort> | range <sPortMin> <sPortMax> ] {{ <dIpAddr>
<dMask> } | any-destination | {host-destination <dIpAddr> }} [d-port { <dPort> |
range <dPortMin> <dPortMax> }] [precedence <prec> ] [tos <tos> ][time-range<time-
range-name> ]
access-list <num> {deny | permit} {eigrp | gre | igrp | ipinip | ip | ospf | <protocol-
num> } {{ <sIpAddr> <sMask> } | any-source | {host-source <sIpAddr> }} {{ <dIpAddr>
<dMask> } | any-destination | {host-destination <dIpAddr> }} [precedence <prec> ]
[tos <tos> ][time-range <time-range-name> ]
no access-list <num>
Functions: Create a numeric extended IP access rule to match specific IP protocol or all
IP protocol; if access-list of this coded numeric extended does not exist, thus to create
such a access-list.
Parameters: <num> is the No. of access-list, 100-299; <protocol> is the No. of upper-
layer protocol of ip, 0-255; <sIpAddr> is the source IP address, the format is dotted
decimal notation; <sMask > is the reverse mask of source IP, the format is dotted
decimal notation; <dIpAddr> is the destination IP address, the format is dotted decimal
notation; <dMask> is the reverse mask of destination IP, the format is dotted decimal
notation, attentive position o, ignored position1; <igmp-type>,the type of igmp, 0-15;
<icmp-type>, the type of icmp, 0-255; <icmp-code>, protocol No. of icmp, 0-
255;<prec>, IP priority, 0-7; <tos>, to value, 0-15; <sPort>, source port No., 0-65535;
<sPortMin>, the down boundary of source port; <sPortMax>, the up boundary of
source port; <dPortMin>, the down boundary of destination port; <dPortMax>, the up
boundary of destination port; <dPort>, destination port No., 0-65535; <time-range-
name>, the name of time-range.
Command Mode: Global mode
Default: No access-lists configured.
Usage Guide: When the user assign specific <num> for the first time, ACL of the serial
number is created, then the lists are added into this ACL; the access list which marked
200-299 can configure not continual reverse mask of IP address.
<igmp-type> represent the type of IGMP packet, and usual values please refer to the
following description:
17(0x11): IGMP QUERY packet
18(0x12): IGMP V1 REPORT packet
22(0x16): IGMP V2 REPORT packet
23(0x17): IGMP V2 LEAVE packet
34(0x22): IGMP V3 REPORT packet
19(0x13): DVMR packet

Содержание

Похожие устройства

Скачать