操作
|
命令
|
配置TCP/UDP 协议的扩展访问列表
|
access-list
listnumber
{ permit | deny } { tcp | udp } source-addr
[ source-mask ] dest-addr [ dest-mask ]
[ operator port1 [ port2 ] ]
|
配置ICMP 协议的扩展访问列表
|
access-list listnumber
{ permit | deny } icmp source-addr
[ source-mask ] dest-addr [ dest-mask ]
|
配置其它协议的扩展访问列表
|
access-list
listnumber
{ permit | deny } protocol source-addr
[ source-mask ] dest-addr [ dest-mask ]
|
操作符及语法
|
意义
|
eg portnumber
|
等于端口号portnumber
|
gt portnumber
|
大于端口号portnumber
|
lt portnumber
|
小于端口号portnumber
|
neg portnumber
|
不等于端口号portnumber
|
range portnumber1 portnumber2
|
介于端口号portnumber1 和
portnumber2 之间
|
协议
|
助记符
|
意义及实际值
|
TCP
|
Bgp
Chargen
Cmd
Daytime
Discard
Domain
Echo
Exec
Finger
Ftp
Ftp-data
Gopher
Hostname
Irc
Klogin
Kshell
Login
Lpd
Nntp
Pop2
Pop3
Smtp
Sunrpc
Syslog
Tacacs
Talk
Telnet
Time
Uucp
Whois
Www
|
Border Gateway Protocol (179)
Character generator (19)
Remote commands (rcmd, 514)
Daytime (13)
Discard (9)
Domain Name Service (53)
Echo (7)
Exec (rsh, 512)
Finger (79)
File Transfer Protocol (21)
FTP data connections (20)
Gopher (70)
NIC hostname server (101)
Internet Relay Chat (194)
Kerberos login (543)
Kerberos shell (544)
Login (rlogin, 513)
Printer service (515)
Network News Transport Protocol (119)
Post Office Protocol v2 (109)
Post Office Protocol v3 (110)
Simple Mail Transport Protocol (25)
Sun Remote Procedure Call (111)
Syslog (514)
TAC Access Control System (49)
Talk (517)
Telnet (23)
Time (37)
Unix-to-Unix Copy Program (540)
Nicname (43)
World Wide Web (HTTP, 80)
|
UDP
|
biff
bootpc
bootps
discard
dns
dnsix
echo
mobilip-ag
mobilip-mn
nameserver
netbios-dgm
netbios-ns
netbios-ssn
ntp
rip
snmp
snmptrap
sunrpc
syslog
tacacs-ds
talk
tftp
time
who
xdmcp
|
Mail notify (512)
Bootstrap Protocol Client (68)
Bootstrap Protocol Server (67)
Discard (9)
Mail notify (512)
DNSIX Securit Attribute Token Map (90)
Echo (7)
MobileIP-Agent (434)
MobilIP-MN (435)
Host Name Server (42)
NETBIOS Datagram Service (138)
NETBIOS Name Service (137)
NETBIOS Session Service (139)
Network Time Protocol (123)
Routing Information Protocol (520)
SNMP (161)
SNMPTRAP (162)
SUN Remote Procedure Call (111)
Syslog (514)
TACACS-Database Service (65)
Talk (517)
Trivial File Transfer (69)
Time (37)
Who(513)
X Display Manager Control Protocol (177)
|
操作
|
操作
|
指定接口上过滤接收报文的规则
|
ip access-group listnumber in
|
取消接口上过滤接收报文的规则
|
no ip access-group listnumber in
|
指定接口上过滤发送报文的规则
|
ip access-group listnumber out
|
取消接口上过滤发送报文的规则
|
no ip access-group listnumber out
|