deny (Extended IPv4 ACLs and
IPv6 ACLs)
Use the following syntax to define a TCP or UDP rule that will deny packets:
[ no ] deny { tcp | udp } { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ source-comparison-operators ] { [ host ] Destination_IPaddress [ mask ] | Destination_hostname[ Destination_IPaddress ] [ mask ] | any } [ established ] [ destination-comparison-operators ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define an ICMP rule that will deny packets:
[no]denyicmp{[host]Source_IPaddress[mask]|Source_hostname[Source_IPaddress][mask]|any}{[host]Destination_IPaddress[mask]|Destination_hostname[Destination_IPaddress][mask]|any}[icmp-num|icmp-type][precedence{precedence-name|precedence-value}][tos{tos-name|tos-value}][dscp-matchingdscp-value][dscp-markingdscp-value][802.1p-priority-matching 802.1p-value][802.1p-priority-marking 802.1p-value][internal-priority-marking queuing-priority][802.1p-and-internal-marking priority-value][traffic-policyname][log][mirror]Use the following syntax to define a rule for protocols other than TCP, UDP, or ICMP that will deny packets:
[no]denyip-protocol {[host]Source_IPaddress[mask]|Source_hostname[Source_IPaddress][mask]|any}{[host]Destination_IPaddress[mask]|Destination_hostname[Destination_IPaddress][mask]|any}[precedence{precedence-name|precedence-value}][tos{tos-name|tos-value}][dscp-matchingdscp-value][dscp-markingdscp-value][802.1p-priority-matching 802.1p-value][802.1p-priority-marking 802.1p-value][internal-priority-marking queuing-priority][802.1p-and-internal-marking priority-value][traffic-policyname][log][mirror]Use the following syntax in IPv6 ACLs to define a rule for protocols to deny packets, using either a protocol abbreviation available for IPv6 ACLs or a protocol number:
[no]denyip-protocol {[host]Source_IPaddress[mask]|Source_hostname[Source_IPaddress][mask]|any}{[host]Destination_IPaddress[mask]|Destination_hostname[Destination_IPaddress][mask]|any}[dscp-matchingdscp-value][routing][fragments][dscp-markingdscp-value][802.1p-priority-matching 802.1p-value][802.1p-priority-marking 802.1p-value][internal-priority-marking queuing-priority][traffic-policyname][log][mirror]no sequenceseq-num- ip-protocol
- Specifies the type of IPv4 packet to filter. You can either specify a protocol number (from 0 through 255) or a supported protocol name. For a complete list of protocols, type ? after deny. Supported protocols include:
- source-comparison-operators and destination-comparison-operators
- If you specified
tcporudp, the following optional operators are available:- gt
- Specifies port numbers that are equal to or greater than the port number or that are equal to or greater than the numeric equivalent of the port name you enter after gt.
- lt
- Specifies port numbers that are equal to or less than the port number or that are equal to or less than the numeric equivalent of the port name you enter after lt.
- range
- Specifies all port numbers that are between the first port name or number and the
second name or number you enter following the
rangekeyword. Enter the range as two values separated by a space. The first port number in the range must be less than the last number in the range. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: 23 53 .
- established
- (For TCP rules only) Filter packets that have the Acknowledgment (ACK) or Reset (RST) flag set. This policy applies only to established TCP sessions, not to new sessions.
- precedence{precedence-name|precedence-value}
- Specifies a precedence-name or corresponding precedence-value, as follows:
- tos{tos-name|tos-value}
- Specifies a type of service (ToS). Enter either a supported tos-name or the equivalent tos-value.
- dscp-markingdscp-value
- Assigns the DSCP value that you specify to the packet. Values range from 0 through 63.
- 802.1p-priority-matching 802.1p-value
- Filters by 802.1p priority, for rate limiting. Values range from 0 through 7.
- 802.1p-priority-marking 802.1p-value
- Assigns the 802.1p value that you specify to the packet. Values range from 0 through 7.
- internal-priority-marking queuing-priority
- Assigns the internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
- 802.1p-and-internal-marking priority-value
- Assigns the identical 802.1p value and internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
- traffic-policyname
- Enables the device to limit the rate of inbound traffic and to count the packets and bytes per packet to which ACL deny clauses are applied. For configuration procedures and examples, refer to the chapter "Traffic Policies" in the RUCKUS FastIron QOS and Traffic Management Configuration Guide.
- log
- Enables SNMP traps and Syslog messages for the rule. In addition, logging must be
enabled using the
logging enablecommand.
IPv4 ACL configuration mode
IPv6 ACL configuration mode
Extended ACLs deny traffic according to port protocol, source and destination addresses, and other IPv4 frame content. You can also enable logging and mirroring.
The order of the rules in an ACL is critical, as the first matching rule stops further processing.
The following protocol abbreviations are available for IPv4 extended ACLs:
The following protocol abbreviations are available for IPv6 ACLs:
The following filtering sub-options are available only in IPv4 extended ACLs:
The following filtering sub-options are available only in IPv6 ACLs:If you use a hostname to identify a source or destination address, the system
resolves its IP address and displays only the IP address (without the associated
hostname) in system output, for example, in show command output.
Because the hostname is resolved as an IP address, it can be used in combination
with a mask.
You can specify a mask in either of the following ways:
- Wildcard mask format (for example, 0.0.0.255). The advantage of this format is that it enables you mask any bit, for example by specifying 0.255.0.255.
- Classless Interdomain Routing (CIDR) format, in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.
For IPv4 extended ACLs, the following sub-options are available in match statements when ICMP protocol is configured with an ICMP message type:
- dscp-marking
- dscp-matching
- internal-priority-marking
- 802.1p-priority-marking
- 802.1p-priority-matching
- precedence
- tos
For IPv6, the following sub-options are available in match statements for ICMP protocol and ICMP message type:
On RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.
When specifying type of service (ToS), you can indicate multiple tos-value options by entering the sum of the needed ToS options. For example, to specify both max-reliability and min-delay, enter 10. To specify all options, enter 15. Values range from 0 through 15.
In a rule that includes one or more
of the following parameters, the log keyword is ignored:
dscp-matchingdscp-marking802.1p-priority-matching802.1p-priority-marking802.1p-and-internal-marking
For details on 802.1p priority matching, refer to "Inspecting the 802.1p bit in the ACL for adaptive rate limiting" in the RUCKUS FastIron QoS and Traffic Management Configuration Guide.
To delete a deny rule from an ACL,
type no followed
by the full command syntax.
The following ACL, applied to an Ethernet interface, blocks and logs IPv4 TCP packets transmitted by Telnet from a specified host.
device# configure terminal device(config)# ip access-list extended block_telnet device(config-ext-ipacl-block_telnet )# deny tcp host 10.157.22.26 any eq telnet log device(config-ext-ipacl-block_telnet)# exit device(config)# interface ethernet 1/1/1 device(config-if-1/1/1)# ip access-group block_telnet in