Netgear GSM7224v1 GSM7212 Command line reference manual - Page 246

access-list

Page 246 highlights

Command Line Interface Reference for the ProSafe 7200 Series Layer-2 Switches, Software Ver- • Wildcard masking for ACLs operates differently from a subnet mask. A wildcard mask is in essence the inverse of a subnet mask. With a subnet mask, the mask has ones (1's) in the bit positions that are used for the network address, and has zeros (0's) for the bit positions that are not used. In contrast, a wildcard mask has (0's) in a bit position that must be checked. A '1' in a bit position of the ACL mask indicates the corresponding bit can be ignored. 14.8.1 access-list This command creates an IP Access Control List (ACL) that is identified by the ACL number. The IP ACL number is an integer from 1 to 99 for an IP standard ACL and from 100 to 199 for an IP extended ACL. The IP ACL rule is specified with either a permit or deny action. The protocol to filter for an IP ACL rule is specified by giving the protocol to be used like icmp,igmp,ip,tcp,udp. The command specifies a source IP address and source mask for match condition of the IP ACL rule specified by the srcip and srcmask parameters. The source layer 4 port match condition for the IP ACL rule is specified by the port value parameter. The range of values is from 0 to 65535. The parameter uses a single keyword notation and currently has the values of domain, echo, ftp, ftpdata, http, smtp, snmp, telnet, tftp, and www. Each of these values translates into its equivalent port number, which is used as both the start and end of a port range. The command specifies a destination IP address and destination mask for match condition of the IP ACL rule specified by the dstip and dstmask parameters. The command specifies the TOS for an IP ACL rule depending on a match of precedence or DSCP values using the parameters dscp, precedence, tos/tosmask. The command specifies the assign-queue which is the queue identifier to which packets matching this rule are assigned. Default none IP Standard ACL: Format Mode access-list {deny | permit} {every | } [assign-queue ] Global Config 14-36 Quality of Service (QoS) Commands v1.0, February 2007

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284

Command Line Interface Reference for the ProSafe 7200 Series Layer-2 Switches, Software Ver-
14-36
Quality of Service (QoS) Commands
v1.0, February 2007
Wildcard masking for ACLs operates differently from a subnet mask. A wildcard
mask is in essence the inverse of a subnet mask. With a subnet mask, the mask has
ones (1's) in the bit positions that are used for the network address, and has zeros (0's)
for the bit positions that are not used. In contrast, a wildcard mask has (0’s) in a bit
position that must be checked. A ‘1’ in a bit position of the ACL mask indicates the
corresponding bit can be ignored.
14.8.1 access-list
This command creates an IP Access Control List (ACL) that is identified by the ACL
number
.
The IP ACL number is an integer from 1 to 99 for an IP standard ACL and from 100 to
199 for an IP extended ACL.
The IP ACL rule is specified with either a
permit or deny
action.
The protocol to filter for an IP ACL rule is specified by giving the protocol to be used like
i
cmp,igmp,ip,tcp,udp.
The command specifies a source IP address and source mask for match condition of the IP
ACL rule specified by the
srcip
and
srcmask
parameters.
The source layer 4 port match condition for the IP ACL rule is specified by the
port value
parameter. The range of values is from 0 to 65535.
The <
portvalue>
parameter uses a single keyword notation and currently has the values
of
domain, echo, ftp, ftpdata, http, smtp, snmp, telnet, tftp
, and
www
. Each
of these values translates into its equivalent port number, which is used as both the start
and end of a port range.
The command specifies a destination IP address and destination mask for match condition
of the IP ACL rule specified by the
dstip
and
dstmask
parameters.
The command specifies the TOS for an IP ACL rule depending on a match of precedence
or DSCP values using the parameters
dscp,
precedence
,
tos/tosmask
.
The command specifies the assign-queue which is the queue identifier to which packets
matching this rule are assigned.
Default
none
IP Standard ACL:
Format
access-list
<1-99> {deny | permit} {every | <srcip>
<srcmask>} [assign-queue <queue-id>]
Mode
Global Config