Specifications
14-10 Security ACL Commands
Parameters
acl‐name SecurityACLname.ACLnamesmustbeuniquewithintheRoamAbout
Switch,muststartwithaletter,andarecase‐insensitive.SpecifyanACL
nameofupto32ofthefollowingcharacters:
•LettersathroughzandAthroughZ
•Numbers0through9
•Hyphen(‐),underscore(_),and
period(.)
Enterasys Networksrecommendsthatyoudonotusethesamenamewith
differentcapitalizationsforACLs.Forexample,donotconfiguretwo
separateACLswiththenamesacl_123andACL_123.
Note: In an ACL name, do not include the term all, default-action, map, help, or
editbuffer.
permit Allowstrafficthat matchestheconditionsintheACE.
coscos Forpermittedpackets, aclass‐of‐service(CoS)levelforpackethandling.
Specifyavaluefrom0through7:
• 1or2—Background.PacketsarequeuedinAPforwardingqueue4.
• 0or3—Besteffort.PacketsarequeuedinAP
forwardingqueue3.
• 4or5—Video.PacketsarequeuedinAPforwardingqueue2.
UseCoSlevel4or5forvoiceoverIP(VoIP)packetsotherthanSpectraLink
VoicePriority(SVP).
• 6or7—Voice.Packetsarequ euedinAPforwardingqueue1.
Use6or7onlyforVoIPphones
thatuseSVP,notforothertypesoftraffic
deny BlockstrafficthatmatchestheconditionsintheACE.
protocol IPprotocolbywhichtofilterpackets:
• ip
• tcp
• udp
• icmp
•Aprotocolnumberbetween0and255.
(ForacompletelistofIPprotocolnamesandnumbers,seewww.iana.org/
assignments/protocol‐numbers.)
source‐
ip‐addrmask IPaddressand wildcardmaskofthenetworkorhostfromwhichthepacket
isbeingsent.Specifybothaddressandmaskindotteddecimalnotation.For
moreinformation,see“WildcardMasks”onpage 1‐3.