Dell PowerSwitch S4112F-ON OS10 Enterprise Edition User Guide Release 10.4.0ER - Page 505
deny tcp (IPv6
View all Dell PowerSwitch S4112F-ON manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 505 highlights
- byte - (Optional) Count bytes the filter processes. - dscp value - (Optional) Deny a packet based on the DSCP values, from 0 to 63. - fragment - (Optional) Use ACLs to control packet fragments. - ack - (Optional) Set the bit as acknowledgement. - fin - (Optional) Set the bit as finish-no more data from sender. - psh - (Optional) Set the bit as push. - rst - (Optional) Set the bit as reset. - syn - (Optional) Set the bit as synchronize. - urg - (Optional) Set the bit set as urgent. • operator - (Optional) Enter a logical operator to match the packets on the specified port number. The following options are available: - eq - Equal to - gt - Greater than - lt - Lesser than - neq - Not equal to - range - Range of ports, including the specified port numbers. • host ip-address - (Optional) Enter the keyword and the IP address to use a host address only. Default Command Mode Usage Information Example Not configured IPV4-ACL OS10 cannot count both packets and bytes; when you use the count byte options, only bytes increment. The no version of this command removes the filter. OS10(config)# ip access-list testflow OS10(conf-ipv4-acl)# deny tcp any any capture session 1 Supported Releases 10.2.0E or later deny tcp (IPv6) Configures a filter that drops TCP IPv6 packets meeting the filter criteria. Syntax Parameters deny tcp [A::B | A::B/x | any | host ipv6-address [operator]] [A::B | A:B/x | any | host ipv6-address [operator]] [ack | fin | psh | rst | syn | urg] [capture | count [byte] | dscp value | fragment] • A::B - Enter the IPv6 address in hexadecimal format separated by colons. • A::B/x - Enter the number of bits to match to the IPv6 address. • any - (Optional) Set all routes which are subject to the filter: - capture - (Optional) Capture packets the filter processes. - count - (Optional) Count packets the filter processes. - byte - (Optional) Count bytes the filter processes. - dscp value - (Optional) Deny a packet based on the DSCP values, from 0 to 63. - fragment - (Optional) Use ACLs to control packet fragments. • operator - (Optional) Enter a logical operator to match the packets on the specified port number. The following options are available: - eq - Equal to - gt - Greater than Access Control Lists 505