TP-Link T1600G-18TS T1600G-18TSUN V2 CLI Reference Guide Guide - Page 373

access-list ip

Page 373 highlights

40.4 access-list ip Description The access-list ip command is used to add IP ACL rule. To delete the corresponding rule, please use no access-list ip command. IP ACLs analyze and process data packets based on a series of match conditions, which can be the source IP addresses and destination IP addresses carried in the packets. Syntax access-list ip acl-id-or-name rule {auto | rule-id } {deny | permit} logging {enable | disable} [ sip sip-address sip-mask sip-address-mask ] [ dip dip-address dip-mask dip-address-mask ] [dscp dscp-value] [tos tos-value] [pre pre-value] [protocol protocol [s-port s-port-number] [s-port-mask s-port-mask] [d-port d-port-number] [d-port-mask d-port-mask] [tcpflag tcpflag]] [tseg time-range-name] no access-list ip acl-id-or-name rule rule-id Parameter acl-id-or-name -- Enter the ID or name of the ACL that you want to add a rule for. auto -- The rule ID will be assigned automatically and the interval between rule IDs is 5. rule-id -- Assign an ID to the rule. deny | permit -- Specify the action to be taken with the packets that match the rule. By default, it is set to permit. The packets will be discarded if "deny" is selected and forwarded if "permit" is selected. logging {enable | disable} -- Enable or disable Logging function for the ACL rule. If "enable " is selected, the times that the rule is matched will be logged every 5 minutes. With ACL Counter trap enabled, a related trap will be generated if the matching times changes. sip-address -- Enter the source IP address. sip-address-mask -- Enter the mask of the source IP address. This is required if a source IP address is entered. dip-address -- Enter the destination IP address. dip-address-mask -- Enter the mask of the destination IP address. This is required if a destination IP address is entered. dscp-value -- Specify the DSCP value between 0 and 63. 352

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483

352
40.4
access-list ip
Description
The
access-list ip
command is used to add IP ACL rule. To delete the
corresponding rule, please use
no access-list ip
command. IP ACLs analyze
and process data packets based on a series of match conditions, which can
be the source IP addresses and destination IP addresses carried in the
packets.
Syntax
access-list ip
acl-id-or-name
rule {
auto
|
rule-id
} {
deny | permit
} logging
{
enable | disable
} [ sip
sip-address
sip-mask
sip-address-mask
] [ dip
dip-address
dip-mask
dip-address-mask
] [dscp
dscp-value
] [tos
tos-value
]
[pre
pre-value
] [protocol
protocol
[s-port
s-port-number
] [s-port-mask
s-port-mask
] [d-port
d-port-number
] [d-port-mask
d-port-mask
] [tcpflag
tcpflag
]] [tseg
time-range-name
]
no access-list ip
acl-id-or-name
rule
rule-id
Parameter
acl-id-or-name
—— Enter the ID or name of the ACL that you want to add a
rule for.
auto —— The rule ID will be assigned automatically and the interval between
rule IDs is 5.
rule-id
—— Assign an ID to the rule.
deny | permit —— Specify the action to be taken with the packets that match
the rule. By default, it is set to permit. The packets will be discarded if “deny”
is selected and forwarded if “permit” is selected.
logging {
enable | disable
}
—— Enable or disable Logging function for the ACL
rule. If "enable " is selected, the times that the rule is matched will be logged
every 5 minutes. With ACL Counter trap enabled, a related trap will be
generated if the matching times changes.
sip-address
—— Enter the source IP address.
sip-address-mask
——
Enter the mask of the source IP address. This is
required if a source IP address is entered.
dip-address
——
Enter the destination IP address.
dip-address-mask
——
Enter the mask of the destination IP address. This is
required if a destination IP address is entered.
dscp-value
——
Specify the DSCP value between 0 and 63.