Administrator Guide

Version Description
9.0.2.0 Introduced on the S6000.
8.3.11.1 Introduced on the Z9000.
8.1.1.0 Introduced on the E-Series (IPv4).
7.8.1.0 Increased the name string to accept up to 140 characters. Prior to 7.8.1.0, names were up
to 16 characters long.
7.6.1.0 Introduced on the S-Series.
7.5.1.0 Introduced on the C-Series.
7.4.1.0 Introduced on the E-Series.
Usage Information
When all sequence numbers are exhausted, this feature permits re-assigning a new sequence number to entries of
an existing access-list.
seq
Assign a sequence number to a deny or permit lter in an extended IP access list while creating the lter.
Syntax
seq sequence-number {deny | permit} {ip-protocol-number | icmp | ip | tcp |
udp} {source mask | any | host ip-address} {destination mask | any | host ip-
address} [operator [portnumber ]] [ttl operator] [count [byte] | log] [dscp
value] [ecn value] [fragments] [monitor [session-ID]] [no-drop] [order]
Parameters
sequence-number Enter a number from 0 to 4294967290.
deny Enter the keyword deny to congure a lter to drop packets meeting this condition.
permit Enter the keyword permit to congure a lter to forward packets meeting this criteria.
ip-protocol-number Enter a number from 0 to 255 to lter based on the protocol identied in the IP protocol
header.
icmp Enter the keyword icmp to congure an ICMP access list lter.
ip Enter the keyword ip to congure a generic IP access list. The keyword ip species that
the access list permits all IP protocols.
tcp Enter the keyword tcp to congure a TCP access list lter.
udp Enter the keyword udp to congure a UDP access list lter.
source Enter an IP address in dotted decimal format of the network from which the packet was
received.
mask (OPTIONAL) Enter a network mask in /prex format (/x) or A.B.C.D. The mask, when
specied in A.B.C.D format, may be either contiguous or non-contiguous.
any Enter the keyword any to specify that all routes are subject to the lter.
host ip-address Enter the keyword host and then enter the IP address to specify a host IP address or
hostname.
operator (OPTIONAL) Enter one of the following logical operands:
eq = equal to
220 Access Control Lists (ACL)