User's Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
45-15
mac-ip-access-list extended <name>
no mac-ip-access-list extended <name>
Creates an extended name-
based MAC-IP access rule;
the no form command delet
es this name-based extende
d MAC-IP access rule.
b. Specify multiple “permit” or “deny” rule entries
Command
Explanation
Extended name-based MAC-IP access Mode
[no]{deny|permit} {any-source-mac|{host-source-m
ac <host_smac>}|{<smac><smac-mask>}} {any-des
tination-mac|{host-destination-mac <host_dmac>}|
{<dmac><dmac-mask>}}icmp {{<source><source-wi
ldcard>}|any-source| {host-source<source-host-i
p>}} {{<destination><destination-wildcard>}|any-de
stination| {host-destination <destination-host-ip>}}
[<icmp-type> [<icmp-code>]] [precedence <prece
dence>][tos<tos>][time-range<time-range-name>]
Creates an extended name-
based MAC-ICMP access ru
le; the no form command d
eletes this name-based exte
nded MAC-ICMP access rul
e.
[no]{deny|permit}{any-source-mac|{host-source-ma
c <host_smac>}|{<smac><smac-mask>}} {any-desti
nation-mac|{host-destination-mac <host_dmac>}|{<
dmac><dmac-mask>}}igmp {{<source><source-wild
card>}|any-source| {host-source<source-host-ip>}}
{{<destination><destination-wildcard>}|any-destinati
on| {host-destination <destination-host-ip>}} [<igm
p-type>] [precedence <precedence>] [tos <tos>][ti
me-range<time-range-name>]
Creates an extended name-
based MAC-IGMP access ru
le; the no form command d
eletes this name-based exte
nded MAC-IGMP access rul
e.
[no]{deny|permit}{any-source-mac|{host-source-ma
c<host_smac>}|{<smac><smac-mask>}} {any-destin
ation-mac|{host-destination-mac <host_dmac>}|{<d
mac><dmac-mask>}}tcp {{<source><source-wild
card>}|any-source| {host-source<source-host-ip>}}
[s-port {<port1> | range <sPortMin> <sPortMa
x>}] {{<destination><destination-wildcard>}|any-des
tination| {host-destination <destination-host-ip>}}
[d-port {<port3> | range <dPortMin> <dPortMax>}]
[ack+fin+psh+rst+urg+syn] [precedence<preceden
ce>][tos<tos>][time-range<time-range-name>]
Creates an extended name-
based MAC-TCP access rul
e; the no form command d
eletes this name-based exte
nded MAC-TCP access rule.