АМАТЕК AN-SGM28P24-400 [227/322] Acl repository configuration

АМАТЕК AN-SGM28P24-400 [227/322] Acl repository configuration
226 / 322
17.3 ACL repository configuration
The switch defaults without any rules
The resource library in the switch supports four types of ACL rules: Standard IP rules,
extended IP rules, IP MAC groups, and ARP groups. Here are four rules to introduce the
configuration of ACL
Standard IP rule: the standard IP rule is to control the forwarding of data packets through the
source IP address
Command formaccess-list <groupId> {deny | permit} <source>
Parameter description
groupIdThe access control list number, standard IP ACL support from 1 to 99 or 1300 to
1999
deny/permitIf the match is complete, the packet is rejected or allowed to be forwarded
sourceSource IP has three input modes
1)A.B.C.D wildcard You can control the IP address from a network segment
2)any Amount to A.B.C.D 255.255.255.255
3)host A.B.C.D Amount to A.B.C.D 0.0.0.0
wildcardDetermine which bits needs to match, '0' indicates the need for matching, and '1'
indicates no need for matching
Extended IP rule: extending the IP rule is an extension of the standard IP rule. The packet
forwarding can be controlled by source IP, destination IP, IP protocol type and service port
Command formaccess-list <groupId> {deny | permit} <protocol> <source> [eq <srcPort>]
<destination> [destPort] <tcp-flag>
Parameter description
groupIdThe access control list number, the extended IP ACL support from 100 to 199 or
2000 to 2699
deny/permitIf the match is complete, the packet is rejected or allowed to be forwarded
protocolThe protocol types over the IP layer, such as TCP, UDP, and so on, can also input
the corresponding number 6 (TCP). If you don't need to control these protocols, you can enter IP
or 0
sourceSource IP has three input modes

Содержание

Похожие устройства

Скачать
Случайные обсуждения