sequence (permit | deny in
Extended IPv4 ACLs)
Use the following syntax to define a TCP or UDP rule:
[sequence seq-num ] { deny | permit } { tcp | udp } { S_IPaddress [ mask ] | host S_IPaddress | any } [ source-comparison-operators ] { D_IPaddress [ mask ] | host D_IPaddress | any } [ established ] [ destination-comparison-operators ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define an ICMP rule:
[ sequence seq-num ] { deny | permit } icmp { S_IPaddress [ mask ] | host S_IPaddress | any } { D_IPaddress [ mask ] | host D_IPaddress | any } [ icmp-num | icmp-type ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define a rule for protocols other than TCP, UDP, or ICMP:
[ sequence seq-num ] { deny | permit } ip-protocol { S_IPaddress[mask]|hostS_IPaddress | any } { D_IPaddress [ mask ] | host D_IPaddress | any } [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]no sequence seq-num- ip-protocol
- Specifies the type of IPv4 packet to filter. You can either specify a protocol number (from 0 through 255) or a supported protocol name. For a complete list of protocols, type ? after permit or deny. Supported protocols include:
- source-comparison-operators and destination-comparison-operators
- If you specified
tcporudp, the following optional operators are available:- gt
- Specifies port numbers that are equal to or greater than the port number or that are equal to or greater than the numeric equivalent of the port name you enter after gt.
- lt
- Specifies port numbers that are equal to or less than the port number or that are equal to or less than the numeric equivalent of the port name you enter after lt.
- range
- Specifies all port numbers that are between the first port name or number and the
second name or number you enter following the
rangekeyword. Enter the range as two values separated by a space. The first port number in the range must be less than the last number in the range. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: 23 53 .
- established
- (For TCP rules only) Filter packets that have the Acknowledgment (ACK) or Reset (RST) flag set. This policy applies only to established TCP sessions, not to new sessions.
- precedence { precedence-name | precedence-value }
- Specifies a precedence-name or corresponding precedence-value, as follows:
- tos { tos-name | tos-value }
- Specifies a type of service (ToS). Enter either a supported tos-name or the equivalent tos-value.
- dscp-marking dscp-value
- Assigns the DSCP value that you specify to the packet. Values range from 0 through 63.
- 802.1p-priority-matching 802.1p-value
- Filters by 802.1p priority, for rate limiting. Values range from 0 through 7.
- 802.1p-priority-marking 802.1p-value
- Assigns the 802.1p value that you specify to the packet. Values range from 0 through 7.
- internal-priority-marking queuing-priority
- Assigns the internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
- 802.1p-and-internal-marking priority-value
- Assigns the identical 802.1p value and internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
- traffic-policy name
- Enables the device to limit the rate of inbound traffic and to count the packets and bytes per packet to which ACL permit or deny clauses are applied. For configuration procedures and examples, refer to the chapter "Traffic Policies" in the RUCKUS FastIron Traffic Management Configuration Guide.
- log
- Enables SNMP traps and Syslog messages for the rule. In addition, logging must be
enabled using the
logging enablecommand.
IPv4 ACL configuration mode
IPv6 ACL configuration mode
Extended ACLs permit or deny traffic according to source and destination addresses, port protocol, and other IPv4 frame content. You can also enable logging and mirroring.
The order of the rules in an ACL is critical, as the first matching rule stops further processing. When creating rules, specifying sequence values determines the order of rule processing. If you do not specify a sequence value, the rule is added to the end of the list. Such a rule is automatically assigned the next multiple of 10 as a sequence number.
You can specify a mask in either of the following ways:
- Wildcard mask format (for example, 0.0.0.255). The advantage of this format is that it enables you mask any bit, for example by specifying 0.255.0.255.
- Classless Interdomain Routing (CIDR) format, in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.
If you specify
icmp and also specify the
any-icmp-type option, the following QoS options are not available:
dscp-marking,
dscp-matching,
internal-priority-marking,
802.1p-priority-marking, ond
802.1p-priority-matching.
On RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.
When specifying type of service (ToS), you can indicate multiple tos-value options by entering the sum of the needed ToS options. For example, to specify both max-reliability and min-delay, enter 10. To specify all options, enter 15. Values range from 0 through 15.
In a rule that includes one or more of the following parameters, the
log keyword is ignored:
dscp-matchingdscp-marking802.1p-priority-matching802.1p-priority-marking802.1p-and-internal-marking
For details on 802.1p priority matching, refer to "Inspecting the 802.1p bit in the ACL for adaptive rate limiting" in the RUCKUS FastIron Traffic Management Configuration Guide.
The following ACL, applied to an Ethernet interface, blocks and logs IPv4 TCP packets transmitted by Telnet from a specified host to any destination.
device# configure terminal device(config)# ip access-list extended block_telnet device(config-ext-ipacl-block_telnet)# sequence 10 deny tcp host 10.157.22.26 any eq telnet log device(config-ext-ipacl-block_telnet)# sequence 20 permit ip any any device(config-ext-ipacl-block_telnet)# exit device(config)# interface ethernet 1/1/1 device(config-if-1/1/1)# ip access-group block_telnet in