
ACCESS-LIST 12 - 9
12.1.2 permit
ip-access-list
Permits specific packets
Supported in the following platforms:
• RFS7000
• RFS6000
• RFS4000
• AP71xx
• AP650
• AP6511
• AP6532
Syntax
permit[icmp|ip|tcp|upd|proto]
permit proto [<0-255>|<WORD>|eigrp|gre|igmp|igp|ospf|vrrp][<source-IP/
Mask>|any|host <IP>][<dest-IP/Mask>|any|host <IP>] {log}
{rule-description
<WORD>|rule-precedence<1-5000>}
{mark [8021p <0-7>|
dscp <0-63>]{rule-description <WORD>|rule-precedence<1-5000>}}
]
permit [tcp|udp] [<source-IP/Mask>|host <IP>|any] [<dest-IP/Mask>|host <IP>|any] {eq
<1-65535> | range <1-65535> <1-65535>} {eq [<1-65535> | <WORD>|/jointfilesconvert/422517/bgp|dns|ftp|ftp
|gopher|https|ldap|nntp|ntp|pop3|smtp|ssh | telnet |tftp| www}|range <1-
65535>|log|mark [8021p <0-7>|dscp <0-63>] rule-precedence <1-5000> {rule-description}
<WORD> |rule-precedence <1-5000> {rule-description} <WORD>}
permit [icmp|ip] [<source-IP/Mask>|any|host <IP>] [<dest-IP/Mask>|any|host <IP>]
{any[<0-255> <0-255>} {log} {mark [8021p <0-7>|dscp<0-63> rule-precedence <1-5000>
{rule-description} <WORD> } {rule-precedence <1-5000> {rule-description} <WORD>}
NOTE: Use a decimal value representation of ethertypes to implement a permit/deny
designation for a packet. The command set for IP ACLs provide the hexadecimal values
for each listed ethertype. The controller supports all ethertypes. Use the decimal
equivalent of the ethertype listed for any other ethertype.
Kommentare zu diesen Handbüchern