permit (Extended IPv4 ACLs and IPv6 ACLs)

Inserts filtering rules to permit packets in IPv4 extended named or numbered ACLs or IPv6 ACLs.
Syntax

Use the following syntax to define a TCP or UDP rule that will permit packets:

[ no ] permit { tcp | udp } { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ source-comparison-operators ] { [host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ established ] [ destination-comparison-operators ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax to define an ICMP rule that will permit packets:

[ no ] permit icmp { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ icmp-num | icmp-type ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax to define a rule for protocols other than TCP, UDP, or ICMP that will permit packets:

[ no ] permit ip-protocol { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax in IPv6 ACLs to define a rule for protocols to permit packets, using either a protocol abbreviation available for IPv6 ACLs or a protocol number:

[ no ] permit ip-protocol { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ dscp-matching dscp-value ] [ routing ] [ fragments ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]
no sequence seq-num
Parameters
ip-protocol
Specifies the type of IPv4 packet to filter. You can either specify a protocol number (from 0 through 255) or a supported protocol name. For a complete list of protocols, type ? after permit. Supported protocols include:
  • icmp—Internet Control Message Protocol
  • igmp—Internet Group Management Protocol
  • igrp—Internet Gateway Routing Protocol
  • ip—any IPv4 protocol
  • ospf—Open Shortest Path First
  • tcp—Transmission Control Protocol
  • udp—User Datagram Protocol
Source_IPaddress
Specifies a source address for which you want to filter the subnet.
mask
Defines a mask, whose effect is to specify a subnet that includes the source address that you specified. For options to specify the mask, see the Usage Guidelines.
host
Depending on placement in the command, specifies the source or destination as a host.
Source_hostname
Specifies the known hostname of the source host.
Destination_hostname
Specifies the known hostname of the destination host.
any
Specifies all source addresses.
source-comparison-operators and destination-comparison-operators
If you specified tcp or udp, the following optional operators are available:
eq
Specifies the address is equal to the port name or number you enter after eq.
gt
Specifies port numbers that are equal to or greater than the port number or that are equal to or greater than the numeric equivalent of the port name you enter after gt.
lt
Specifies port numbers that are equal to or less than the port number or that are equal to or less than the numeric equivalent of the port name you enter after lt.
neq
Specifies all port numbers except the port number or port name you enter after neq.
range
Specifies all port numbers that are between the first port name or number and the second name or number you enter following the range keyword. Enter the range as two values separated by a space. The first port number in the range must be less than the last number in the range. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: 23 53 .
Destination_IPaddress
Specifies a destination address for which you want to filter the subnet.
mask
Defines a subnet mask that includes the destination address that you specified. For mask options, refer to the Usage Guidelines.
any
Specifies all destination addresses.
established
(For TCP rules only) Filter packets that have the Acknowledgment (ACK) or Reset (RST) flag set. This policy applies only to established TCP sessions, not to new sessions.
icmp-num | icmp-type
(For ICMP only) Specifies a named or numbered message type.
icmp-num
Specifies a numbered message type. Use this format if the rule also needs to include precedence, tos , one of the DSCP options, one of the 802.1p options, internal-priority-marking , or traffic-policy.
any-icmp-type
Specifies any ICMP type.
echo
Specifies an echo request (ping).
echo-reply
Specifies an echo reply.
information-request
Specifies an information request.
mask-reply
Specifies an address mask reply.
mask-request
Specifies an address mask request.
parameter-problem
Specifies a parameter problem.
redirect
Specifies a redirect message.
source-quench
Specifies a relieve congestion message.
time-exceeded
Specifies a time exceeded message.
timestamp-reply
Specifies a timestamp reply.
timestamp-request
Specifies a timestamp request.
unreachable
Specifies a destination-unreachable message.
precedence { precedence-name | precedence-value }
Specifies a precedence-name or corresponding precedence-value, as follows:
0 or routine
Specifies routine precedence.
1 or priority
Specifies priority precedence.
2 or immediate
Specifies immediate precedence.
3 or flash
Specifies flash precedence.
4 or flash-override
Specifies flash-override precedence.
5 or critical
Specifies critical precedence.
6 or internet
Specifies internetwork control precedence.
7 or network
Specifies network control precedence.
tos { tos-name | tos-value }
Specifies a type of service (ToS). Enter either a supported tos-name or the equivalent tos-value.
0 or normal
Specifies normal ToS.
1 or min-monetary-cost
Specifies min monetary cost ToS.
2 or max-reliability
Specifies max reliability ToS.
4 or max-throughput
Specifies max throughput ToS.
8 or min-delay
Specifies min-delay ToS.
fragments
Filters on IPv6 fragments with a non-zero fragment offset.
routing
Filters on IPv6 packets routed from the source.
dscp-matching dscp-value
Filters by DSCP value. Values range from 0 through 63.
dscp-marking dscp-value
Assigns the DSCP value that you specify to the packet. Values range from 0 through 63.
802.1p-priority-matching 802.1p-value
Filters by 802.1p priority, for rate limiting. Values range from 0 through 7.
802.1p-priority-marking 802.1p-value
Assigns the 802.1p value that you specify to the packet. Values range from 0 through 7.
internal-priority-marking queuing-priority
Assigns the internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
802.1p-and-internal-marking priority-value
Assigns the identical 802.1p value and internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
traffic-policy name
Enables the device to limit the rate of inbound traffic and to count the packets and bytes per packet to which ACL permit clauses are applied. For configuration procedures and examples, refer to the chapter "Traffic Policies" in the RUCKUS FastIron Traffic Management Configuration Guide.
log
Enables SNMP traps and Syslog messages for the rule. In addition, logging must be enabled using the logging enable command.
mirror
Mirrors packets matching the rule.
Modes

IPv4 ACL configuration mode

IPv6 ACL configuration mode

Usage Guidelines

Extended ACLs permit traffic according to source and destination addresses, port protocol, and other IPv4 frame content. You can also enable logging and mirroring.

The order of the rules in an ACL is critical, as the first matching rule stops further processing.

Note: Although both IPv4 extended ACLs and IPv6 ACLs can reference any protocol by its protocol number, the available protocol abbreviations differ between IPv4 extended ACLs and IPv6 ACLs,

The following protocol abbreviations are available for IPv4 extended ACLs:

  • esp
  • gre
  • icmp
  • igmp
  • ip
  • ipv6
  • ospf
  • pim
  • rsvp
  • tcp
  • udp

The following protocol abbreviations are available for IPv6 ACLs:

  • ahp
  • esp
  • icmp
  • ipv6
  • sctp
  • tcp
  • udp

A few filtering sub-options are available only in IPv4 or IPv6 ACLs.

The following filtering sub-options are available only in IPv4 extended ACLs:

  • precedence
  • tos
  • 802.1p-and-internal-marking

The following filtering sub-options are available only in IPv6 ACLs:

  • fragments
  • routing

If you use a hostname to identify a source or destination address, the system resolves its IP address and displays only the IP address (without the associated hostname) in system output, for example, in show command output. Because the hostname is resolved as an IP address, it can be used in combination with a mask.

You can specify a mask in either of the following ways:

  • Wildcard mask format (for example, 0.0.0.255). The advantage of this format is that it enables you mask any bit, for example by specifying 0.255.0.255.
  • Classless Interdomain Routing (CIDR) format, in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.

For IPv4 extended ACLs, the following sub-options are available in match statements when ICMP protocol is configured with an ICMP message type:

  • dscp-marking
  • dscp-matching
  • internal-priority-marking
  • 802.1p-priority-marking
  • 802.1p-priority-matching
  • precedence
  • tos

For IPv6, the following sub-options are available in match statements for ICMP protocol and ICMP message type:

  • dscp-marking
  • dscp-matching

For RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.

When specifying type of service (ToS), you can indicate multiple tos-value options by entering the sum of the needed ToS options. For example, to specify both max-reliability and min-delay, enter 10. To specify all options, enter 15. Values range from 0 through 15.

In a rule that includes one or more of the following parameters, the log keyword is ignored:

  • dscp-matching
  • dscp-marking
  • 802.1p-priority-matching
  • 802.1p-priority-marking
  • 802.1p-and-internal-marking

For details on 802.1p priority matching, refer to "Inspecting the 802.1p bit in the ACL for adaptive rate limiting" in the RUCKUS FastIron QoS and Traffic Management Configuration Guide.

To delete a permit rule from an ACL, type no followed by the full command syntax.

Examples
device# configure terminal
device(config)# ip access-list extended blocktelnet
device(config-ext-ipacl-blocktelnet)# no permit ip any any
device(config-ext-ipacl-blocktelnet)# interface ethernet 1/1/1
device(config-if-1/1/1)# ip access-group blocktelnet in