HP BladeSystem bc2800 Command Line Interface Reference Guide HP BladeSystem PC - Page 61

deny (IP

Page 61 highlights

ACL Commands deny (IP) The deny IP-Access List Configuration mode command denies traffic if the conditions defined in the deny statement match. Syntax deny [disable-port] {any | protocol} {any | {source source-wildcard}} {any | {destination destination-wildcard}} [dscp dscp number | ip-precedence ip-precedence] deny {any | protocol} {any | {source source-wildcard}} {any | {destination destination-wildcard}} [dscp dscp-number | ip-precedence ip-precedence] deny-icmp {any | {source source-wildcard}} {any | {destination destination-wildcard}} {any | icmp-type} {any | icmp-code} [dscp number | ip-precedence number] deny-igmp {any | {source source-wildcard}} {any | {destination destination-wildcard}} {any | igmp-type} [dscp number | ip-precedence number] Parameters n disable-port - Specifies that the port should be disabled if the conditions defined match. n source - Specifies the IP address or host name from which the packet was sent. Specify any to indicate IP address 0.0.0.0 and mask 255.255.255.255. n source-wildcard - Specifies wildcard bits by placing 1s in bit positions to be ignored. Specify any to indicate IP address 0.0.0.0 and mask 255.255.255.255. n destination - Specifies the IP address or host name to which the packet is being sent. Specify any to indicate IP address 0.0.0.0 and mask 255.255.255.255. n destination-wildcard - Specifies wildcard bits by placing 1s in bit positions to be ignored. Specify any to indicate IP address 0.0.0.0 and mask 255.255.255.255. n protocol - Specifies the abbreviated name or number of an IP protocol. The following table lists protocols that can be specified: IP Protocol Internet Control Message Protocol Internet Group Management Protocol IP in IP (encapsulation) Protocol Transmission Control Protocol Exterior Gateway Protocol Interior Gateway Protocol User Datagram Protocol Host Monitoring Protocol Reliable Data Protocol Inter-Domain Policy Routing Protocol Ipv6 Protocol Routing Header for IPv6 Fragment Header for IPv6 Abbreviated Name icmp igmp ipinip tcp egp igp udp hmp rdp idpr ipv6 ipv6-route ipv6-frag Protocol Number 1 2 4 6 8 9 17 20 27 35 41 43 44 HP PC Blade Switch CLI Reference Guide www.hp.com 4-5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434

HP PC Blade Switch CLI Reference Guide
www.hp.com
4-5
ACL Commands
deny (IP)
The
deny
IP-Access List Configuration mode command denies
traffic if the conditions defined in
the deny statement match.
Syntax
deny [disable-port]
{
any
|
protocol
} {
any
| {
source source-wildcard
}} {
any
| {
destination
destination-wildcard
}} [
dscp
dscp number
|
ip-precedence
ip-precedence
]
deny
{
any | protocol
} {
any
| {
source
source-wildcard
}} {
any
| {
destination
destination-wildcard
}} [
dscp
dscp-number
|
ip-precedence
ip-precedence
]
deny-icmp
{any | {
source
source-wildcard
}} {
any
| {
destination
destination-wildcard
}} {
any
|
icmp-type
} {
any
|
icmp-code
} [
dscp
number
|
ip-precedence
number
]
deny-igmp
{
any
| {
source
source-wildcard
}} {
any
| {
destination
destination-wildcard
}} {
any
|
igmp-type
} [
dscp
number
|
ip-precedence
number
]
Parameters
n
disable-port
— Specifies that the port should be disabled if the conditions defined match.
n
source
— Specifies the IP address or host name from which the packet was sent. Specify
any
to indicate IP address 0.0.0.0 and mask 255.255.255.255.
n
source-wildcard
— Specifies wildcard bits by placing 1s in bit positions to be ignored.
Specify
any
to indicate IP address 0.0.0.0 and mask 255.255.255.255.
n
destination
— Specifies the IP address or host name to which the packet is being sent.
Specify
any
to indicate IP address 0.0.0.0 and mask 255.255.255.255.
n
destination-wildcard
— Specifies wildcard bits by placing 1s in bit positions to be ignored.
Specify
any
to indicate IP address 0.0.0.0 and mask 255.255.255.255.
n
protocol
— Specifies the abbreviated name or number of an IP protocol.
The following table lists protocols that can be specified:
IP Protocol
Abbreviated Name
Protocol Number
Internet Control Message Protocol
icmp
1
Internet Group Management Protocol
igmp
2
IP in IP (encapsulation) Protocol
ipinip
4
Transmission Control Protocol
tcp
6
Exterior Gateway Protocol
egp
8
Interior Gateway Protocol
igp
9
User Datagram Protocol
udp
17
Host Monitoring Protocol
hmp
20
Reliable Data Protocol
rdp
27
Inter-Domain Policy Routing Protocol
idpr
35
Ipv6 Protocol
ipv6
41
Routing Header for IPv6
ipv6-route
43
Fragment Header for IPv6
ipv6-frag
44