D-Link DXS-3600-EM-8T CLI Guide - Page 35

Extended Expert Access-list Configuration Mode.

Page 35 highlights

DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide protocol operator port precedence precedence tos tos fragments time-range time-rangename tcp-flag icmp-type icmp-code icmp-message Specifies the name or number of an IP protocol used. Names that can be used are 'eigrp', 'esp', 'gre', 'igmp', 'ip', 'ipinip', 'ospf', 'pcp', 'pim', 'tcp', 'udp', 'icmp' or an integer in the range 0 to 255 representing an IP protocol number. This field is used to match any Internet protocol. There are additional specific parameters for 'tcp', 'udp', and 'icmp'. The 'ip' means any IP Protocol. (Optional) Specifies the operator used. Possible operators include 'eq' (equal), 'gt' (greater than), 'lt' (less than), 'neq' (not equal), and 'range' (inclusive range). A range needs two port numbers, while other operators only need one port number. Specifies the Layer 4 port number as a decimal number (from 0 to 65535) or the name of a L4 port. TCP port names used: 'bgp', 'chargen', 'daytime', 'discard', 'domain', 'echo', 'rexec', 'finger', 'ftp', 'ftp-data', 'gopher', 'hostname', 'ident', 'irc', 'klogin', 'kshell', 'login', 'lpd', 'nntp', 'snpp', 'pop2', 'pop3', 'smtp', 'sunrpc', 'shell', 'tacacs', 'telnet', 'time', 'uucp', 'whois', 'http'. UDP port names used: 'biff', 'bootpc', 'bootps', 'discard', 'irc', 'domain', 'echo', 'isakmp', 'mobile-ip', 'nameserver', 'netbios-dgm', 'netbios-ns', 'netbios-ss', 'nat-t', 'ntp', 'snpp', 'rip', 'snmp', 'snmptrap', 'sunrpc', 'syslog', 'tacacs', 'talk', 'tftp', 'time', 'who', 'xdmcp'. (Optional) Packets can be filtered by their precedence level. This is specified by a number from 0 to 7 or by name. Names that can be used are routine (0), priority (1), immediate (2), flash (3), flash-override (4), critical (5), internet (6), network (7). (Optional) Packets can be filtered by their type of service level. This is specified by a number from 0 to 15 or by name. Names that can be used are normal (0), maxreliability (2), max-throughput (4), min-delay (8), min-monetary-cost (1). (Optional) Specifies packet fragment filtering. (Optional) Specifies the name of the time-period profile associated with the accesslist delineating its activation period. (Optional) Specifies the TCP flag fields. The specified TCP header bits can be 'ack' (acknowledge), 'fin' (finish), 'psh' (push), 'rst' (reset), 'syn' (synchronize), or 'urg' (urgent). (Optional) Specifies the ICMP message type. The valid number for the message type is from 0 to 255. (Optional) Specifies the ICMP message code. The valid number for the message code is from 0 to 255 (Optional) Specifies the ICMP message type name or the ICMP message type and code by name. Names that can be used are 'administratively-prohibited', 'alternateaddress', 'conversion-error', 'host-prohibited', 'net-prohibited', 'echo', 'echo-reply', 'pointer-indicates-error', 'host-isolated', 'host-precedence-violation', 'host-redirect', 'host-tos-redirect', 'host-tos-unreachable', 'host-unknown', 'host-unreachable', 'information-reply', 'information-request', 'mask-reply', 'mask-request', 'mobileredirect', 'net-redirect', 'net-tos-redirect', 'net-tos-unreachable', 'net-unreachable', 'net-unknown', 'bad-length', 'option-missing', 'packet-fragment', 'parameter-problem', 'port-unreachable', 'precedence-cutoff', 'protocol-unreachable', 'reassembly-timeout', 'redirect-message', 'router-advertisement', 'router-solicitation', 'source-quench', 'source-route-failed', 'time-exceeded', 'timestamp-reply', 'timestamp-request', 'traceroute', 'ttl-expired', 'unreachable'. Default Command Mode Command Default Level Usage Guideline None. Extended Expert Access-list Configuration Mode. Level: 12 A sequence number will be assigned automatically if the user did not assign it manually. The automatic assignment sequence number starts from 10 and increases by 10 for every new entry. 27

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576
  • 577
  • 578
  • 579
  • 580
  • 581
  • 582
  • 583
  • 584
  • 585
  • 586
  • 587
  • 588
  • 589
  • 590
  • 591
  • 592
  • 593
  • 594
  • 595
  • 596
  • 597
  • 598
  • 599
  • 600
  • 601
  • 602
  • 603
  • 604
  • 605
  • 606
  • 607
  • 608
  • 609
  • 610
  • 611
  • 612
  • 613
  • 614
  • 615
  • 616
  • 617
  • 618
  • 619
  • 620
  • 621
  • 622
  • 623
  • 624
  • 625
  • 626
  • 627
  • 628
  • 629
  • 630
  • 631
  • 632
  • 633
  • 634
  • 635
  • 636
  • 637
  • 638
  • 639
  • 640
  • 641
  • 642
  • 643
  • 644
  • 645
  • 646
  • 647
  • 648
  • 649
  • 650
  • 651
  • 652
  • 653
  • 654
  • 655
  • 656
  • 657
  • 658
  • 659
  • 660
  • 661
  • 662
  • 663
  • 664
  • 665
  • 666
  • 667
  • 668
  • 669
  • 670
  • 671
  • 672
  • 673
  • 674
  • 675
  • 676
  • 677
  • 678
  • 679
  • 680
  • 681
  • 682
  • 683
  • 684
  • 685
  • 686
  • 687
  • 688
  • 689
  • 690
  • 691
  • 692
  • 693
  • 694
  • 695

DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide
27
protocol
Specifies the name or number of an IP protocol used. Names that can be used are
'eigrp', 'esp', 'gre', 'igmp', 'ip', 'ipinip', 'ospf', 'pcp', 'pim', 'tcp', 'udp', 'icmp' or an integer
in the range 0 to 255 representing an IP protocol number. This field is used to match
any Internet protocol. There are additional specific parameters for ‘tcp’, ‘udp’, and
‘icmp’. The ‘ip’ means any IP Protocol.
operator
(Optional) Specifies the operator used. Possible operators include ‘eq’ (equal), ‘gt’
(greater than), ‘lt’ (less than), ‘neq’ (not equal), and ‘range’ (inclusive range). A range
needs two port numbers, while other operators only need one port number.
port
Specifies the Layer 4 port number as a decimal number (from 0 to 65535) or the
name of a L4 port.
TCP port names used:
'bgp', 'chargen', 'daytime', 'discard', 'domain', 'echo', 'rexec', 'finger', 'ftp', 'ftp-data',
'gopher', 'hostname', 'ident', 'irc', 'klogin', 'kshell', 'login', 'lpd', 'nntp', 'snpp',
'pop2', 'pop3', 'smtp', 'sunrpc', 'shell', 'tacacs', 'telnet', 'time', 'uucp', 'whois',
'http'.
UDP port names used:
'biff', 'bootpc', 'bootps', 'discard', 'irc', 'domain', 'echo', 'isakmp', 'mobile-ip',
'nameserver', 'netbios-dgm', 'netbios-ns', 'netbios-ss', 'nat-t', 'ntp', 'snpp', 'rip',
'snmp', 'snmptrap', 'sunrpc', 'syslog', 'tacacs', 'talk', 'tftp', 'time', 'who', 'xdmcp'.
precedence
precedence
(Optional) Packets can be filtered by their precedence level. This is specified by a
number from 0 to 7 or by name. Names that can be used are routine (0), priority (1),
immediate (2), flash (3), flash-override (4), critical (5), internet (6), network (7).
tos
tos
(Optional) Packets can be filtered by their type of service level. This is specified by a
number from 0 to 15 or by name. Names that can be used are normal (0), max-
reliability (2), max-throughput (4), min-delay (8), min-monetary-cost (1).
fragments
(Optional) Specifies packet fragment filtering.
time-range
time-range-
name
(Optional) Specifies the name of the time-period profile associated with the access-
list delineating its activation period.
tcp-flag
(Optional) Specifies the TCP flag fields. The specified TCP header bits can be ‘ack’
(acknowledge), ‘fin’ (finish), ‘psh’ (push), ‘rst’ (reset), ‘syn’ (synchronize), or ‘urg’
(urgent).
icmp-type
(Optional) Specifies the ICMP message type. The valid number for the message type
is from 0 to 255.
icmp-code
(Optional) Specifies the ICMP message code. The valid number for the message
code is from 0 to 255
icmp-message
(Optional) Specifies the ICMP message type name or the ICMP message type and
code by name. Names that can be used are 'administratively-prohibited', 'alternate-
address', 'conversion-error', 'host-prohibited', 'net-prohibited', 'echo', 'echo-reply',
'pointer-indicates-error', 'host-isolated', 'host-precedence-violation', 'host-redirect',
'host-tos-redirect', 'host-tos-unreachable', 'host-unknown', 'host-unreachable',
'information-reply', 'information-request', 'mask-reply', 'mask-request', 'mobile-
redirect', 'net-redirect', 'net-tos-redirect', 'net-tos-unreachable', 'net-unreachable',
'net-unknown', 'bad-length', 'option-missing', 'packet-fragment', 'parameter-problem',
'port-unreachable', 'precedence-cutoff', 'protocol-unreachable', 'reassembly-timeout',
'redirect-message', 'router-advertisement', 'router-solicitation', 'source-quench',
'source-route-failed', 'time-exceeded', 'timestamp-reply', 'timestamp-request',
'traceroute', 'ttl-expired', 'unreachable'.
Default
None.
Command Mode
Extended Expert Access-list Configuration Mode.
Command Default Level
Level: 12
Usage Guideline
A sequence number will be assigned automatically if the user did not assign it
manually. The automatic assignment sequence number starts from 10 and increases
by 10 for every new entry.