Reference Guide

Table Of Contents
access-list
This command creates an IP ACL that is identified by the access list number, which is 1-99 for standard
ACLs or 100-199 for extended ACLs. Table 14 on page 628 describes the parameters for the access-list
command.
IP Standard ACL:
Format access-list 1-99 {remark comment} | {[sequence-number]} ]
{deny | permit} {every | srcip srcmask | host srcip} [time-
range time-range-name] [log] [assign-queue queue-id] [{mirror
| redirect} unit/slot/port] [rate-limit rate burst-size]
Mode Global Config
IP Extended ACL:
Format access-list 100-199 {remark comment} | {[sequence-number]}
[rule 1-1023] {deny | permit} {every | {{eigrp | gre | icmp |
igmp | ip | ipinip | ospf | pim | tcp | udp | 0 -255} {srcip
srcmask|any|host srcip}[range {portkey|startport} {portkey|
endport} {eq|neq|lt|gt} {portkey|0-65535}{dstip dstmask|any|
host dstip}[{range {portkey|startport} {portkey|endport} |
{eq | neq | lt | gt} {portkey | 0-65535} ] [flag [+fin | -
fin] [+syn | -syn] [+rst | -rst] [+psh | -psh] [+ack | -ack]
[+urg | -urg] [established]] [icmp-type icmp-type [icmp-code
icmp-code] | icmp-message icmp-message] [igmp-type igmp-type]
[fragments] [precedence precedence | tos tos [ tosmask] |
dscp dscp]}} [time-range time-range-name] [log] [assign-queue
queue-id] [{mirror | redirect} unit/slot/port] [rate-limit
rate burst-size]
Mode Global Config
Note
IPv4 extended ACLs have the following limitations for egress ACLs:
Match on port ranges is not supported.
The rate-limit command is not supported.
Quality of Service Commands
ExtremeSwitching 200 Series: Command Reference Guide for version 01 .02.04.0007 627