Specifications

access-list (extended) Configuring Access Lists
Enterasys Matrix N Standalone (NSA) Series Configuration Guide 24-19
Defaults
•Ifinsert,replace,ormovearenotspecified,thenew entrywillbeappendedtotheaccesslist.
•Ifsource2isnotspecifiedwithmove,onlyoneentrywillbemoved.
•Ificmptypeandicmpcodearenotspecified,ICMPparam eterswillbeappliedtoallICMP
messagetypes.
•If
operatorandportarenotspecified,accessparameterswillbeappliedtoallTCPorUDP
ports.
destination Specifiesthenetworkorhosttowhichthepacketwillbesent.Valid
optionsforexpressingdestinationare:
•IPaddress(A.B.C.D)
any‐Anydestinationhost
hostsource‐IPaddressofasingledestination
host
destination
wildcard
(Optional)Specifiesthebitstoignoreinthedestinationaddress.
icmptype (Optional)FiltersICMPframesbyICMPmessage type.Thetypeisa
numberfrom0to255.
icmpcode (Optional)FurtherfiltersICMPframesfilteredbyICMPmessagetype
bytheirICMPmessagecode.Thecodeisa
numberfrom0to255.
operatorport (Optional)AppliesaccessrulestoTCPorUDPsourceordestination
portnumbers.Possibleoperandsinclude:
ltport‐Matchonlypacketswithalowerportnumber.
gtport‐Matchonlypacketswithagreaterportnumber.
eqport‐Matchonlypacketsona
givenportnumber.
neqport‐Matchonlypacketsnotonagivenportnumber.
rangeminsportmaxsportMatchonlypacketsintherangeof
sourceports
rangemindportmaxdportMatchonlypacketsintherangeof
destinationports.
tosextensions (Optional)Appliesaccessrulesto
theprecedenceand/ortosfields,orto
theDiffServfield.Thatis,youcanspecifyoneorbothprecedenceand
tosfields,oryoucanspecifytheDiffServfield.Usethefollowing
keyword/valuepairstospecifythetosextensions:
•precedencevalue(07)‐MatchpacketsbasedontheIPprecedence
value.
tosvalue(015)‐MatchpacketsbasedontheIPTypeofService
value.
dscpvalue(063)‐MatchpacketsbasedontheDiffservcodepoint
value.
established (Optional)AppliesTCPrestrictionstoestablishedconnectionsonly.
log (Optional)Enabletherulebeingconfiguredforsyslog.