User Manual

Table Of Contents
NETGEAR M4500 Series Switches CLI Command Reference Manual 552
flag <value>
Specifies that the IP ACL rule matches on the TCP flags. The value parameter represents :
+fin, -fin, +syn, -syn, +rst, -rst,+psh, -psh, +ack, -ack, +urg, -urg, established.
When + is specified, a match occurs if the specified flag is set in the TCP header. When -
is specified, a match occurs if the specified flag is NOT set in the TCP header. When
established is specified, a match occurs if the specified RST or ACK bits are set in the TCP.
Note: This option is available only if the protocol is TCP.
icmp-type <icmp-
type> [icmp-code
<icmp-code> | icmp-
message <icmp-
message>]
This option is available only if the protocol is ICMP.
Specifies a match condition for ICMP packets.
When icmp-type is specified, the IP ACL rule matches on the specified ICMP message
type, a number from 0 to 255.
When icmp-code is specified, the IP ACL rule matches on the specified ICMP message
code, a number from 0 to 255.
Specifying icmp-message implies that both icmp-type and icmp-code are specified. The
following icmp-messages are supported: echo, echo-reply, host-redirect, mobile-
redirect, net-redirect, net-unreachable, redirect, packet-too-big, port-unreachable,
source-quench, router-solicitation, router-advertisement, time-exceeded, ttl-exceeded
and unreachable.
igmp-type <igmp-
type>
This option is available only if the protocol is IGMP.
When igmp-type is specified, the IP ACL rule matches on the specified IGMP message
type, a number from 0 to 255.
dscp <value>
Specifies the TOS for an IP ACL rule depending on a match of DSCP value using
parameters dscp.
precedence <0-7>
Specifies the TOS for an IP ACL rule depending on a match of precedence values using
parameters <0-7>
tos <tos> [<tosmask>]
Specifies the TOS for an IP ACL rule depending on a match value using parameters
tos/tosmask.
fragments
Specifies that the IP ACL rule matches on fragmented IP packets.
log
Enable logging for this access list rule
time-range-name
Specify the name of the time-range if the IP ACL rule has referenced a time range.
queue-id
Specify the queue identifier to which packets matching this rule are assigned
mirror | redirect
Specify the traffic matching the rule to be copied/redirected to the specific slot/port or
port-channel.
slot/port
The interface number to be mirrored or redirected to.
portchannel-id
The port channel ID to be mirrored or redirected to.