Specifications

Table Of Contents
Chapter 1: acl Commands
1 - 22 SSR Command Line Interface Reference Manual
ready defined as keywords. For example, for Telnet, you can
enter the port number 23 as well as the keyword
telnet
.
<DstPort>
For TCP or UDP, the number of the destination TCP or UDP
port. This field applies only to incoming TCP or UDP traffic.
The same requirements and restrictions for
<SrcPort>
apply
to
<DstPort>
.
<tos>
IP TOS (Type of Service) value. You can specify a TOS from
0 – 15.
Restrictions
When you apply an ACL to an interface, the SSR appends an implicit deny rule to that
ACL. The implicit deny rule denies all traffic. If you intend to allow all traffic that
doesn’t match your specified ACL rules to go through, you must explicitly define a rule
to permit all traffic.
Examples
Here are some examples of ACL commands for permitting and denying UDP traffic
flows.
ssr(config)# acl 100 permit udp 10.1.3.0/24 any
Creates an ACL to permit UDP traffic from the subnet 10.1.3.0 (with a 24 bit
netmask) to any destination.
ssr(config)# acl notftp deny udp any any tftp any
Creates an ACL to deny any incoming TFTP traffic.
ssr(config)# acl udpnfs permit udp 10.12.0.0/16 10.7.0.0/16 any
nfs
Creates an ACL to permit UDP based NFS traffic from subnet 10.12.0.0 to subnet
10.7.0.0.