HP GbE2c HP GbE2c Ethernet Blade Switch for c-Class BladeSystem ISCLI Referenc - Page 132

ACL Ethernet Filter configuration, ethernet-type {ARP|IP|IPv6|MPLS - vrrp example

Page 132 highlights

ACL Ethernet Filter configuration These commands allow you to define Ethernet matching criteria for an ACL. The following table describes the Ethernet Filter Configuration commands. Table 154 Ethernet Filter Configuration commands Command Description access-control list ethernet source-mac-address {} Defines the source MAC address and MAC mask for this ACL. For example: 00:60:cf:40:56:00 ff:ff:ff:ff:ff:fc Command mode: Global configuration access-control list ethernet destination-mac-address {} Defines the destination MAC address and MAC mask for this ACL. For example: 00:60:cf:40:56:00 ff:ff:ff:ff:ff:fc Command mode: Global configuration access-control list ethernet vlan Defines a VLAN number and mask for this ACL. Command mode: Global configuration access-control list ethernet ethernet-type {ARP|IP|IPv6|MPLS| RARP|any|0xXXXX} Defines the Ethernet type for this ACL. Command mode: Global configuration access-control list ethernet priority Defines the Ethernet priority value for the ACL. Command mode: Global configuration default access-control list ethernet Resets Ethernet parameters for the ACL to their default values. Command mode: Global configuration show access-control list {} ethernet Displays the current Ethernet parameters for the ACL. Command mode: All except User EXEC ACL IP Version 4 Filter configuration These commands allow you to define IPv4 matching criteria for an ACL. The following table describes the IP version 4 Filter Configuration commands. Table 155 IPv4 Filter Configuration commands Command Description access-control list ipv4 source-ip-address {} Defines a source IP address for the ACL. If defined, traffic with this source IP address will match this ACL. Specify an IP address in dotted decimal notation. Command mode: Global configuration access-control list ipv4 destination-ip-address {} Defines a destination IP address for the ACL. If defined, traffic with this destination IP address will match this ACL. Command mode: Global configuration access-control list ipv4 protocol Defines an IP protocol for the ACL. If defined, traffic from the specified protocol matches this filter. Specify the protocol number. Listed below are some of the well-known protocols. Number Name 1 icmp 2 igmp 6 tcp 17 udp 89 ospf 112 vrrp Command mode: Global configuration access-control list ipv4 type-of-service Defines a Type of Service value for the ACL. For more information on ToS, see RFC 1340 and 1349. Command mode: Global configuration default access-control list ipv4 Resets the IPv4 parameters for the ACL to their default values. Command mode: Global configuration Configuration Commands 132

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153

Configuration Commands 132
ACL Ethernet Filter configuration
These commands allow you to define Ethernet matching criteria for an ACL. The following table describes the Ethernet
Filter Configuration commands.
Table 154
Ethernet Filter Configuration commands
Command
Description
access-control list <
1-762
> ethernet
source-mac-address <
MAC address
> {
<
MAC
mask
>}
Defines the source MAC address and MAC mask for this ACL.
For example:
00:60:cf:40:56:00 ff:ff:ff:ff:ff:fc
Command mode:
Global configuration
access-control list <
1-762
> ethernet
destination-mac-address <
MAC address
>
{
<
MAC mask
>}
Defines the destination MAC address and MAC mask for this
ACL. For example:
00:60:cf:40:56:00 ff:ff:ff:ff:ff:fc
Command mode:
Global configuration
access-control list <
1-762
> ethernet
vlan <
1-4095
> <
mask
>
Defines a VLAN number and mask for this ACL.
Command mode:
Global configuration
access-control list <
1-762
> ethernet
ethernet-type {ARP|IP|IPv6|MPLS|
RARP|any|0xXXXX}
Defines the Ethernet type for this ACL.
Command mode:
Global configuration
access-control list <
1-762
> ethernet
priority <
0-7
>
Defines the Ethernet priority value for the ACL.
Command mode:
Global configuration
default access-control list <
1-762
>
ethernet
Resets Ethernet parameters for the ACL to their default values.
Command mode:
Global configuration
show access-control list {<
1-762
>}
ethernet
Displays the current Ethernet parameters for the ACL.
Command mode:
All except User EXEC
ACL IP Version 4 Filter configuration
These commands allow you to define IPv4 matching criteria for an ACL. The following table describes the IP version 4
Filter Configuration commands.
Table 155
IPv4 Filter Configuration commands
Command
Description
access-control list <
1-762
>
ipv4 source-ip-address <
IP
address
> {<
IP mask
>}
Defines a source IP address for the ACL. If defined, traffic with this source IP
address will match this ACL. Specify an IP address in dotted decimal notation.
Command mode:
Global configuration
access-control list <
1-762
>
ipv4 destination-ip-address
<
IP address
> {<
IP mask
>}
Defines a destination IP address for the ACL. If defined, traffic with this
destination IP address will match this ACL.
Command mode:
Global configuration
access-control list <
1-762
>
ipv4 protocol <
0-255
>
Defines an IP protocol for the ACL. If defined, traffic from the specified protocol
matches this filter. Specify the protocol number. Listed below are some of the
well-known protocols.
Number
Name
1
icmp
2
igmp
6
tcp
17
udp
89
ospf
112
vrrp
Command mode:
Global configuration
access-control list <
1-762
>
ipv4 type-of-service <
0-255
>
Defines a Type of Service value for the ACL. For more information on ToS, see
RFC 1340 and 1349.
Command mode:
Global configuration
default access-control list
<
1-762
> ipv4
Resets the IPv4 parameters for the ACL to their default values.
Command mode:
Global configuration