TP-Link T2600G-52TS TL-SG3452 T2600G-28TS V1 CLI Reference Guide - Page 217
access-list extended
View all TP-Link T2600G-52TS TL-SG3452 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 217 highlights
time-segment -- The time-range for the rule to take effect. By default, it is not limited. Command Mode Global Configuration Mode Example Create a Standard-IP ACL whose ID is 520, and add Rule 10 for it. In the rule, the source IP address is 192.168.0.100, the source IP address mask is 255.255.255.0, the time-range for the rule to take effect is "tRange1", and the packets match this rule will be forwarded by the switch: T2600G-28TS(config)# access-list create 520 T2600G-28TS(config)# access-list standard 520 rule 10 permit sip 192.168.0.100 smask 255.255.255.0 tseg tSeg1 29.9 access-list extended Description The access-list extended command is used to add Extended-IP ACL rule. To delete the corresponding rule, please use no access-list extended command. Syntax access-list extended acl-id rule rule-id { deny | permit } [[ sip source-ip ] smask source-ip-mask ] [[ dip destination-ip] dmask destination-ip-mask ] [ tseg time-segment ] [frag {disable | enable}] [ dscp dscp ] [ s-port s-port ] [ d-port d-port ] [ tcpflag tcpflag ] [ protocol protocol ] [ tos tos ] [ pre pre ] no access-list extended acl-id rule rule-id Parameter acl-id--The desired Extended-IP ACL for configuration. rule-id -- The rule ID. deny -- The operation to discard packets. permit --The operation to forward packets. It is the default value. source-ip -- The source IP address contained in the rule. source-ip-mask -- The source IP address mask. It is required if you typed the source IP address. destination-ip -- The destination IP address contained in the rule. destination-ip-mask -- The destination IP address mask. It is required if you typed the destination IP address. 201