Specifications
Table Of Contents
- Title Page
- Notice
- Contents
- acl Commands
- acl-edit Commands
- aging Commands
- arp Commands
- cli Commands
- configure Command
- copy Command
- dvmrp Commands
- enable Command
- erase Command
- exit Command
- file Commands
- filters Commands
- http Commands
- igmp Commands
- interface Commands
- ip Commands
- ip-router Commands
- Command Summary
- ip-router authentication add key-chain
- ip-router authentication create key-chain
- ip-router global add
- ip-router global set
- ip-router global set trace-options
- ip-router global set trace-state
- ip-router global use provided_config
- ip-router kernel trace
- ip-router policy add filter
- ip-router policy add optional-attributes-list
- ip-router policy aggr-gen destination
- ip-router policy create aggregate-export-source
- ip-router policy create aggr-gen-dest
- ip-router policy create aggr-gen-source
- ip-router policy create aspath-export-source
- ip-router policy create bgp-export-destination
- ip-router policy create bgp-export-source
- ip-router policy create bgp-import-source
- ip-router policy create direct-export-source
- ip-router policy create filter
- ip-router policy create optional-attributes-list
- ip-router policy create ospf-export-destination
- ip-router policy create ospf-export-source
- ip-router policy create ospf-import-source
- ip-router policy create rip-export-destination
- ip-router policy create rip-export-source
- ip-router policy create rip-import-source
- ip-router policy create static-export-source
- ip-router policy create tag-export-source
- ip-router policy export destination
- ip-router policy import source
- ip-router policy redistribute
- ip-router show configuration file
- ip-router show state
- ipx Commands
- l2-tables Commands
- logout Command
- multicast Commands
- mtrace Command
- negate Command
- no Command
- ospf Commands
- Command Summary
- ospf add interface
- ospf add nbma-neighbor
- ospf add network
- ospf add stub-host
- ospf add virtual-link
- ospf create area
- ospf create-monitor
- ospf monitor
- ospf set area
- ospf set ase-defaults
- ospf set export-interval
- ospf set export-limit
- ospf set interface
- ospf set monitor-auth-method
- ospf set trace-options
- ospf set virtual-link
- ospf show
- ospf start|stop
- ping Command
- port Commands
- qos Commands
- reboot Command
- rip Commands
- save Command
- show Command
- snmp Commands
- statistics Commands
- stp Commands
- system Commands
- Command Summary
- system image add
- system image choose
- system image delete
- system image list
- system promimage upgrade
- system set bootprom
- system set contact
- system set date
- system set dns
- system set location
- system set name
- system set password
- system set poweron-selftest
- system set syslog
- system set terminal
- system show
- traceroute Command
- vlan Commands

Chapter 1: acl Commands
SSR Command Line Interface Reference Manual 1 - 21
acl permit|deny udp
Purpose
Create a UDP ACL.
Format
acl
<name>
permit|deny udp
<SrcAddr/Mask> <DstAddr/Mask>
<SrcPort> <DstPort> <tos>
Mode
Configure
Description
The
acl
permit
udp
and
acl
deny
udp
commands define an ACL to allow or block
UDP traffic from entering or leaving the SSR. For each of the values describing a flow,
you can use the keyword
any
to specify a wildcard (“don’t care”) condition. If you do
not specify a value for a field, the SSR applies a wildcard condition to the field, giving
the same effect as if you specify the
any
keyword.
Parameters
<name>
Name of this ACL. You can use a string of characters or a
number.
<SrcAddr/Mask>
The source address and the filtering mask of this flow. If the
source address is a network or subnet address, you must sup-
ply the filtering mask. Generally, the filtering mask is the net-
work mask of this network or subnet. If the source address is
that of a host then no mask is required. By default, if a mask
is not supplied, the source address is treated as that of a host.
You can specify the mask using the traditional IP address for-
mat (“255.255.0.0”) or the CIDR format (“/16”).
<DstAddr/Mask>
The destination address and the filtering mask of this flow.
The same requirements and restrictions for
<SrcAddr/Mask>
apply to
<DstAddr/Mask>
.
<SrcPort>
For TCP or UDP, the number of the source TCP or UDP port.
This field applies only to incoming TCP or UDP traffic.
You
can specify a range of port numbers using operator symbols;
for example, 10-20 (between 10 and 20 inclusive), >1024
(greater than 1024), <1024 (les than 1024), !=1024 (not equal
to 1024). The port numbers of some popular services are al-