Reference Guide

246 Network Security
deny protocol {any |{source-prefix/length}
{any | destination-prefix/length} [dscp
number | precedence number] [time-range
time-range-name] [disable-port | log-
input]
deny icmp {any {source-prefix/length} {any
| destination-prefix/length} {any | icmp-
type} {any | icmp-code} [dscp number |
precedence number] [time-range time-range-
name] [disable-port | log-input]
deny tcp {any | {source-prefix/length} {any
| source-port/port-range}} {any |
destination-prefix/length} {any |
destination-port/port-range} [dscp number
| precedence number] [match-all list-of-
flags] [time-range time-range-name]
[di
sable-port |
log-input]
deny udp {any | {source-prefix/length}}
{any | source-port/port-range}} {any |
destination-prefix/length} {any |
destination-port/port-range} [dscp number
| precedence number] [time-range time-
range-name] [disable-port | log-input]
Sets deny conditions
for IPv6 access list (in
Access List
Configuration mode).
Table 9-7. IP-Based ACE CLI Commands
(continued)
CLI Command Description