Specifications
access-list (extended) Configuring Access Lists
Enterasys Matrix N Standalone (NSA) Series Configuration Guide 24-19
Defaults
•Ifinsert,replace,ormovearenotspecified,thenew entrywillbeappendedtotheaccesslist.
•Ifsource2isnotspecifiedwithmove,onlyoneentrywillbemoved.
•Ificmp‐typeandicmp‐codearenotspecified,ICMPparam eterswillbeappliedtoallICMP
messagetypes.
•If
operatorandportarenotspecified,accessparameterswillbeappliedtoallTCPorUDP
ports.
destination Specifiesthenetworkorhosttowhichthepacketwillbesent.Valid
optionsforexpressingdestinationare:
•IPaddress(A.B.C.D)
• any‐Anydestinationhost
• hostsource‐IPaddressofasingledestination
host
destination‐
wildcard
(Optional)Specifiesthebitstoignoreinthedestinationaddress.
icmp‐type (Optional)FiltersICMPframesbyICMPmessage type.Thetypeisa
numberfrom0to255.
icmp‐code (Optional)FurtherfiltersICMPframesfilteredbyICMPmessagetype
bytheirICMPmessagecode.Thecodeisa
numberfrom0to255.
operatorport (Optional)AppliesaccessrulestoTCPorUDPsourceordestination
portnumbers.Possibleoperandsinclude:
• ltport‐Matchonlypacketswithalowerportnumber.
• gtport‐Matchonlypacketswithagreaterportnumber.
• eqport‐Matchonlypacketsona
givenportnumber.
• neqport‐Matchonlypacketsnotonagivenportnumber.
• rangemin‐sportmax‐sport‐Matchonlypacketsintherangeof
sourceports
• rangemin‐dportmax‐dport‐Matchonlypacketsintherangeof
destinationports.
tos‐extensions (Optional)Appliesaccessrulesto
theprecedenceand/ortosfields,orto
theDiffServfield.Thatis,youcanspecifyoneorbothprecedenceand
tosfields,oryoucanspecifytheDiffServfield.Usethefollowing
keyword/valuepairstospecifythetos‐extensions:
•precedencevalue(0‐7)‐MatchpacketsbasedontheIPprecedence
value.
• tosvalue(0‐15)‐MatchpacketsbasedontheIPTypeofService
value.
• dscpvalue(0‐63)‐MatchpacketsbasedontheDiffservcodepoint
value.
established (Optional)AppliesTCPrestrictionstoestablishedconnectionsonly.
log (Optional)Enabletherulebeingconfiguredforsyslog.