Motorola 2.1 User Manual Page 438

  • Download
  • Add to my manuals
  • Print
  • Page
    / 713
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 437
Extended ACL Instance 14-23
Usage Guidelines
Use this command to permit traffic between network’s/host’s based on the protocol type selected in the access list
configuration. The following protocols are supported:
•IP
•ICMP
•TCP
•UDP
The last ACE in the access list is an implicit deny statement.
Whenever the interface receives the packet, its content is checked against all the ACE’s in the ACL. It is allowed based
on the ACL configuration.
Filtering on Protocol types TCP/UDP allows the user to specify port numbers as filtering criteria.
Select the protocol type ICMP to allow ICMP packets. Selecting ICMP allows filtering of ICMP packets based on
the ICMP type and code.
Example
The example below allows IP traffic from the source subnet to destination subnet and denies all other traffic over an
interface.
RFS7000(config-ext-nacl)#permit ip 192.168.1.10/24 192.168.2.0/24 rule-precedence 40
RFS7000(config-ext-nacl)#
The example below allows ICMP based traffic and denies all other traffic over an interface.
RFS7000(config-ext-nacl)#permit icmp any any rule-precedence 30
RFS7000(config-ext-nacl)#)#
NOTE The log option is functional only for router ACLs. The log option causes an
informational logging message about the packet matching the entry sent to the
console.
Page view 437
1 2 ... 433 434 435 436 437 438 439 440 441 442 443 ... 712 713

Comments to this Manuals

No comments