Reference Guide

Table Of Contents
Parameter Description
[precedence precedence | tos tos [tosmask] |
dscp dscp]
Specifies the TOS for an IP ACL rule depending on a match of
precedence or DSCP values using the parameters dscp,
precedence, tos/tosmask.
tosmask is an optional parameter.
flag [+fin | -fin] [+syn | -syn] [+rst | -rst] [+psh | -
psh] [+ack | -ack] [+urg | -urg] [established]
Specifies that the IP ACL rule matches on the tcp flags.
When +tcpflagname is specified, a match occurs if the
specified tcpflagname flag is set in the TCP header.
When -tcpflagname is specified, a match occurs if the
specified tcpflagname flag is NOT set in the TCP header.
When established is specified, a match occurs if either the
specified RST or ACK bits are set in the TCP header. Two rules
are installed in hardware to when the established option is
specified.
This option is available only if protocol is tcp.
[icmp-type icmp-type [icmp-code icmp-code]
| icmp-message icmp-message]
This option is available only if the protocol is ICMP.
Specifies a match condition for ICMP packets.
When icmp-type is specified, IP ACL rule matches on the
specified ICMP message type, a number from 0 to 255.
When icmp-code is specified, IP ACL rule matches on the
specified ICMP message code, a number from 0 to 255.
Specifying icmp-message implies both icmp-type and icmp-
code are specified. The following icmp-messages are
supported: echo, echo-reply, host-redirect, mobile-redirect,
net-redirect, net-unreachable, redirect, packet-too-big, port-
unreachable, source-quench, router-solicitation, router-
advertisement, time-exceeded, ttl-exceeded and
unreachable.
The ICMP message is decoded into corresponding ICMP type
and ICMP code within that ICMP type.
igmp-type igmp-type This option is visible only if the protocol is IGMP.
When igmp-type is specified, the IP ACL rule matches on the
specified IGMP message type, a number from 0 to 255.
fragments Specifies that IP ACL rule matches on fragmented IP packets.
ttl eq Specifies that the IP ACL rule matches on packets with the
specified Time To Live (TTL) value.
log Specifies that this rule is to be logged.
time-range time-range-name Allows imposing a time limitation on the ACL rule as defined
by the parameter time-range-name. If a time range with the
specified name does not exist and the ACL containing this
ACL rule is applied to an interface or bound to a VLAN, the
ACL rule is applied immediately. If a time range with specified
name exists and the ACL containing this ACL rule is applied
to an interface or bound to a VLAN, the ACL rule is applied
when the time-range with specified name becomes active.
The ACL rule is removed when the time-range with specified
name becomes inactive.
assign-queue queue-id Specifies the assign-queue, which is the queue identifier to
which packets matching this rule are assigned.
rate-limit rate burst-size Specifies the allowed rate of trac as per the configured rate
in kbps, and burst-size in kbytes.
Quality of Service Commands
ExtremeSwitching 200 Series: Command Reference Guide for version 01 .02.04.0007 635