Juniper Networks EX2500 Switch User Manual


 
EX2500 Ethernet Switch Configuration Guide
54 Using ACL Filters
IP Extended ACLs
The switch supports up to 128 IP ACLs (standard and extended), numbered from
128 through 254. Use IP Extended ACLs to filter traffic using the following criteria:
Source IP address or network mask
Destination IP address or network mask
IP protocol number or name as shown in Table 12
TCP/UDP application ports, as shown in Table 13 on page 55
TCP flags
ICMP message code and type
Type of Service (ToS) value
DSCP value
To create an IP Extended ACL:
ex2500(config)# access-list ip 128 extended
ex2500(config-ext-nacl)#
To delete an IP Extended ACL:
ex2500(config)# no access-list ip 128 extended
ex2500(config)#
Table 12: Well-Known Protocol Types
Number Protocol Name
1
4
6
17
89
103
icmp
ip
tcp
udp
ospf
pim