Access Security Guide K/KA/KB.15.15

extended:configure, 271
extended:numbered, configure, 271
mask:CIDR, 69
ACL, IPv4
802.1X client limit, 309
802.1X, effect on;802.1X:ACL, effect on;ACL,
IPv4:user-based 802.1X;ACL, IPv4:port-based 802.1X,
309
ACE, order in list, 318
ACE:after match not used, 318, 330
ACE:insert in list;ACL, IPv4:sequence number:use to
insert ACE, 288
ACE:limit, 321
ACE:not used, 315
application methods, 317
application points, 313, 317
applications, 305, 313, 327
assign nonexistent i.d., 331
assigning to a VLAN;ACL, IPv4:removing from a VLAN,
282
assigning to a VLAN;ACL:removing from a VLAN, 281
assignment not deleted, 288
basic structure, 328
CIDR:mask, 326
CIDR:mask bits, IP address, 260, 262
clear statistics, 296
command syntax, 259
configured but not used, 331
configured but not used;ACL, IPv4:assigning to a VLAN,
331
configuring: offline, 312
connection-rate ACL, 306, 307, 310
copy operation appends, 285
counter on multiple interfaces, 299
create, CLI method, 283
defined, 301
deleting from config, 288
deny any
implicit, 312, 316
mplicit, IPv6, 308
deny any, implicit, 312, 316
deny any, implicit, supersede;supersede implicit deny
any, 328
deny any: implicit, 303, 317, 318, 321, 328
display:ACLs and assignments, 281
display:assignments, 277
display:configuration details, 276
display:summary, configured ACLs, 276
dynamic port join, 322
dynamic port joins to a VLAN, 322
dynamic VLAN;VLAN:dynamic, 322
editing, 319
effect of replacing;ACL, IPv4:replacing active ACEs,
331
established, 268
established;ACL, IPv4:TCP, established, 327
exception for connection-rate filtering;connection-rate
filtering:exception for, configuring, 312
exit statement;ACL, IPv4:end, 331
extended:configure, 263
extended:numeric I.D. range, 328
extended:protocol options, 327
extended:structure, 329
extended:use, 306
features, common to all, 312
filter rule when RACL, VACL, and/or port ACL all apply,
311
filtering methods;ACL, IPv4:applications, 306
filtering process, 315
hit count, 295
host option, 325
ICMP:configure, 275
ICMP:options, 275
ICMP:traffic, 313
ICMP:type;ACL, IPv4:ICMP:code, 275
IGMP:configure, 270
IGMP:traffic, 313
IGMP:type, 275
implicit deny, 312
interface assignment, options, 302
IPv4 routing requirement for RACL, 313
limit, 225, 263
log message, 332
logging, 260, 312
logging:described, 332
logging:session, 312
mask, 260, 312, 323
mask:CIDR, 326
mask:one IP address, 325
match: always;ACL, IPv4:deny any: implicit;, 331
match: criteria, 323
match: example, 324
match: ignored;ACL, IPv4:filtering process, 318
maximum allowed, 321
maximum allowed: IPv4 and IPv6, 319
mirroring;mirroring;port monitoring, ACL, 307
multiple ACLs on interface;ACL, IPv4:permit: with
multiple ACLs, 310
multiple applications;ACL, IPv4:applications, 310
multiple lists on an interface;ACL, IPv4:packet screened
by multiple lists, 311
multiple on same interface, 310
name or number assignment;, 331
name string, maximum characters, 327
named: character limit;ACL:character limit, 318
named: rule, 283
non-IPv4 traffic;ACL, IPv4:AppleTalk;ACL:IPX;ACL,
IPv4:traffic: not filtered, 318
nonexistent i.d., assign, 331
number of entries, 312
numbered:manage as named, 319
numbered:rule, 284
operator, comparison; , 268
override implicit deny, 316
permit/deny policies: defined;ACL,
IPv4:standard:defined;ACL,
IPv4:extended:defined;ACL, IPv4:policy, permit/deny,
327
525