XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
45-10
[no] {deny | permit} icmp {{<sIpAddr> <sMask>} |
any-source | {host-source <sIpAddr>}} {{<dIpAdd
r> <dMask>} | any-destination | {host-destination
<dIpAddr>}} [<icmp-type> [<icmp-code>]] [precede
nce <prec>] [tos <tos>][time-range<time-range-na
me>]
Creates an extended name-
based ICMP IP access rule;
the no form command dele
tes this name-based extend
ed IP access rule.
[no] {deny | permit} igmp {{<sIpAddr> <sMask>} |
any-source | {host-source <sIpAddr>}} {{<dIpAdd
r> <dMask>} | any-destination | {host-destination
<dIpAddr>}} [<igmp-type>] [precedence <prec>] [t
os <tos>][time-range<time-range-name>]
Creates an extended name-
based IGMP IP access rule;
the no form command dele
tes this name-based extend
ed IP access rule.
[no] {deny | permit} tcp {{<sIpAddr> <sMask>} | a
ny-source | {host-source <sIpAddr>}} [s-port {<sP
ort> | range <sPortMin> <sPortMax>}] {{<dIpAdd
r> <dMask>} | any-destination | {host-destination
<dIpAddr>}} [d-port {<dPort> | range <dPortMin>
<dPortMax>}] [ack+fin+psh+rst+urg+syn] [precede
nce <prec>] [tos <tos>][time-range<time-range-na
me>]
Creates an extended name-
based TCP IP access rule;
the no form command delet
es this name-based extende
d IP access rule.
[no] {deny | permit} udp {{<sIpAddr> <sMask>} |
any-source | {host-source <sIpAddr>}} [s-port {<s
Port> | range <sPortMin> <sPortMax>}] {{<dIpAdd
r> <dMask>} | any-destination | {host-destination
<dIpAddr>}} [d-port {<dPort> | range <dPortMin>
<dPortMax>}] [precedence <prec>] [tos <tos>][tim
e-range<time-range-name>]
Creates an extended name-
based UDP IP access rule;
the no form command delet
es this name-based extende
d IP access rule.
[no] {deny | permit} {eigrp | gre | igrp | ipinip | i
p | ospf | <protocol-num>} {{<sIpAddr> <sMask>}
| any-source | {host-source <sIpAddr>}} {{<dIpAd
dr> <dMask>} | any-destination | {host-destination
<dIpAddr>}} [precedence <prec>] [tos <tos>][time
-range<time-range-name>]
Creates an extended name-
based IP access rule for ot
her IP protocols; the no for
m command deletes this na
me-based extended IP acce
ss rule.
c. Exit extended IP ACL configuration mode
Command
Explanation
Extended IP ACL Mode
exit
Exits extended name-based
IP ACL configuration mod
e.