permit (Extended IPv4 ACLs and
IPv6 ACLs)
Use the following syntax to define a TCP or UDP rule that will permit packets:
[ no ] permit { tcp | udp } { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ source-comparison-operators ] { [host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ established ] [ destination-comparison-operators ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define an ICMP rule that will permit packets:
[ no ] permit icmp { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ icmp-num | icmp-type ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define a rule for protocols other than TCP, UDP, or ICMP that will permit packets:
[ no ] permit ip-protocol { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax in IPv6 ACLs to define a rule for protocols to permit packets, using either a protocol abbreviation available for IPv6 ACLs or a protocol number:
[ no ] permit ip-protocol { [ host ] Source_IPaddress [ mask ] | Source_hostname [ Source_IPaddress ] [ mask ] | any } { [ host ] Destination_IPaddress [ mask ] | Destination_hostname [ Destination_IPaddress ] [ mask ] | any } [ dscp-matching dscp-value ] [ routing ] [ fragments ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]no sequence seq-num- ip-protocol
- Specifies the type of IPv4 packet to filter. You can either specify a protocol number (from 0 through 255) or a supported protocol name. For a complete list of protocols, type ? after permit. Supported protocols include:
- source-comparison-operators and destination-comparison-operators
- If you specified
tcporudp, the following optional operators are available:- gt
- Specifies port numbers that are equal to or greater than the port number or that are equal to or greater than the numeric equivalent of the port name you enter after gt.
- lt
- Specifies port numbers that are equal to or less than the port number or that are equal to or less than the numeric equivalent of the port name you enter after lt.
- range
- Specifies all port numbers that are between the first port name or number and the
second name or number you enter following the
rangekeyword. Enter the range as two values separated by a space. The first port number in the range must be less than the last number in the range. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: 23 53 .
- established
- (For TCP rules only) Filter packets that have the Acknowledgment (ACK) or Reset (RST) flag set. This policy applies only to established TCP sessions, not to new sessions.
- precedence { precedence-name | precedence-value }
- Specifies a precedence-name or corresponding precedence-value, as follows:
- tos { tos-name | tos-value }
- Specifies a type of service (ToS). Enter either a supported tos-name or the equivalent tos-value.
- dscp-marking dscp-value
- Assigns the DSCP value that you specify to the packet. Values range from 0 through 63.
- 802.1p-priority-matching 802.1p-value
- Filters by 802.1p priority, for rate limiting. Values range from 0 through 7.
- 802.1p-priority-marking 802.1p-value
- Assigns the 802.1p value that you specify to the packet. Values range from 0 through 7.
- internal-priority-marking queuing-priority
- Assigns the internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
- 802.1p-and-internal-marking priority-value
- Assigns the identical 802.1p value and internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
- traffic-policy name
- Enables the device to limit the rate of inbound traffic and to count the packets and bytes per packet to which ACL permit clauses are applied. For configuration procedures and examples, refer to the chapter "Traffic Policies" in the RUCKUS FastIron Traffic Management Configuration Guide.
- log
- Enables SNMP traps and Syslog messages for the rule. In addition, logging must be
enabled using the
logging enablecommand.
IPv4 ACL configuration mode
IPv6 ACL configuration mode
Extended ACLs permit traffic according to source and destination addresses, port protocol, and other IPv4 frame content. You can also enable logging and mirroring.
The order of the rules in an ACL is critical, as the first matching rule stops further processing.
The following protocol abbreviations are available for IPv4 extended ACLs:
The following protocol abbreviations are available for IPv6 ACLs:
A few filtering sub-options are available only in IPv4 or IPv6 ACLs.
The following filtering sub-options are available only in IPv4 extended ACLs:
The following filtering sub-options are available only in IPv6 ACLs:
If you use a hostname to identify a source or
destination address, the system resolves its IP address and displays only the
IP
address (without the associated hostname) in system output, for example, in show command output.
Because the hostname is resolved as an IP address, it can be used in combination
with a mask.
You can specify a mask in either of the following ways:
- Wildcard mask format (for example, 0.0.0.255). The advantage of this format is that it enables you mask any bit, for example by specifying 0.255.0.255.
- Classless Interdomain Routing (CIDR) format, in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.
For IPv4 extended ACLs, the following sub-options are available in match statements when ICMP protocol is configured with an ICMP message type:
- dscp-marking
- dscp-matching
- internal-priority-marking
- 802.1p-priority-marking
- 802.1p-priority-matching
- precedence
- tos
For IPv6, the following sub-options are available in match statements for ICMP protocol and ICMP message type:
For RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.
When specifying type of service (ToS), you can indicate multiple tos-value options by entering the sum of the needed ToS options. For example, to specify both max-reliability and min-delay, enter 10. To specify all options, enter 15. Values range from 0 through 15.
In a rule that includes one or more of the following parameters, the
log keyword is ignored:
dscp-matchingdscp-marking802.1p-priority-matching802.1p-priority-marking802.1p-and-internal-marking
For details on 802.1p priority matching, refer to "Inspecting the 802.1p bit in the ACL for adaptive rate limiting" in the RUCKUS FastIron QoS and Traffic Management Configuration Guide.
To delete a permit rule from an ACL, type
no followed by the full command syntax.