Netgear GSM7312 FSM7326P User Manual - Page 270

Configuration Commands, access-list

Page 270 highlights

User Manual for the NETGEAR 7300 Series Layer 3 Managed Switch Software Configuration Commands access-list This command creates an Access Control List (ACL) that is identified by the parameter . The ACL number is an integer from 1 to 199. The range 1 to 99 is for normal ACL List and 100 to 199 is extended ACL List. The ACL rule is created with the option of permit or deny. The protocol to filter for an ACL rule is specified by giving the protocol to be used like cmp,igmp,ip,tcp,udp. The command specifies a source ip address and source mask for match condition of the ACL rule specified by the srcip and srcmask parameters.The source layer 4 port match condition for the ACL rule are specified by the port value parameter.The and parameters identify the first and last ports that are part of the port range. They have values from 0 to 65535. The ending port must have a value equal or greater than the starting port. The starting port, ending port, and all ports in between will be part of the destination port range.The parameter uses a single keyword notation and currently has the values of domain, echo, ftp, ftpdata, http, smtp, snmp, telnet, tftp, and www. Each of these values translates into its equivalent port number, which is used as both the start and end of a port range. The command specifies a destination ip address and destination mask for match condition of the ACL rule specified by the dstip and dstmask parameters.The command specifies the TOS for an ACL rule depending on a match of precedence or DSCP values using the parameters tos, tosmask, dscp. Default none Format access-list {( {deny | permit} ) | ( { {deny | permit} {evry | {{icmp | igmp | ip | tcp | udp | } [{eq { | } | range }] [{eq { | } | range }] [precedence ] [tos ] [dscp ]}})} Mode Global Config no access-list This command deletes an ACL that is identified by the parameter from the system. Format no access-list 11-2 202-10009-01_060204 CLI Commands: ACL

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364

User Manual for the NETGEAR 7300 Series Layer 3 Managed Switch Software
11-2
CLI Commands: ACL
202-10009-01_060204
Configuration Commands
access-list
This command creates an Access Control List (ACL) that is identified by the parameter
<
accesslistnumber>.
The ACL number is an integer from 1 to 199. The range 1 to 99 is for
normal ACL List and 100 to 199 is extended ACL List. The ACL rule is created with the option of
permit or deny
. The protocol to filter for an ACL rule is specified by giving the protocol to be used
like
cmp,igmp,ip,tcp,udp.
The command specifies a source ip address and source mask for match
condition of the ACL rule specified by the
srcip
and
srcmask
parameters.The source layer 4 port
match condition for the ACL rule are specified by the
port value
parameter.The <
startport>
and
<endport>
parameters identify the first and last ports that are part of the port range. They have
values from 0 to 65535. The ending port must have a value equal or greater than the starting port.
The starting port, ending port, and all ports in between will be part of the destination port
range.The <
portvalue>
parameter uses a single keyword notation and currently has the values of
domain, echo, ftp, ftpdata, http, smtp, snmp, telnet, tftp
, and
www
. Each of these
values translates into its equivalent port number, which is used as both the start and end of a port
range. The command specifies a destination ip address and destination mask for match condition
of the ACL rule specified by the
dstip
and
dstmask
parameters.The command specifies the TOS
for an ACL rule depending on a match of precedence or DSCP values using the parameters
tos,
tosmask, dscp
.
Default
none
Format
access-list {( <1-99> {deny | permit} <srcip> <src-
mask>) | ( {<100-199> {deny | permit} {evry | {{icmp |
igmp | ip | tcp | udp | <number>} <srcip> <srcmask>
[{eq {<portkey> | <portvalue>} | range <startport>
<endport>}] <dstip> <dstmask> [{eq {<portkey> |
<portvalue>} | range <startport> <endport>}] [prece-
dence <precedence>] [tos <tos> <tosmask>] [dscp
<dscp>]}})}
Mode
Global Config
no access-list
This command deletes an ACL that is identified by the parameter <
accesslistnumber>
from the
system
.
Format
no access-list <accesslistnumber>