
12 - 4 WiNG CLI Reference Guide
12.1.1 deny
ip-access-list
Specifies packets to reject
Supported in the following platforms:
• RFS7000
• RFS6000
• RFS4000
• AP71xx
• AP650
• AP6511
• AP6532
Syntax
deny [icmp|ip|proto|tcp|udp]
deny icmp [<source-IP>|any|host <IP>] [<dest-IP>|any|host <IP>] {<ICMP-type> {<ICMP-
code>}} {log} {rule-precedence <1-5000>}] <0-255>
deny ip [<source-IP>|any|host <IP>] [<dest-IP>|any|host <IP>] {log} {rule-precedence
<1-5000>}
deny [tcp|udp] [<source-IP>|any|host <IP>] {eq
<source-port>|range <starting-source-port>
<ending-source-port>} [<dest-IP|any|host <IP>]
{eq <source-port>} {range <starting-source-port>
<ending-source-port>} {eq[<1-65535>|<WORD>|/jointfilesconvert/422517/bgp|dns|ftp|ftp
|gopher|https|ldap|nntp|ntp|pop3|smtp|ssh | telnet |tftp| www} {log} {rule-precedence
<1-5000>
deny proto
[<0-254>|<WORD>|eigrp|gre|igmp|igp|ospf|vrrp][<source-IP/
Mask>|any|host <IP>][<dest-IP/Mask>|any|host <IP>] {log} {rule-description
<WORD>|rule-precedence<1-5000>}
NOTE: Use a decimal value representation of ethertypes to implement a permit/deny
designation for a packet. The command set for IP ACLs provide the hexadecimal values
for each listed ethertype. The controller supports all ethertypes. Use the decimal
equivalent of the ethertype listed for any other ethertype.
Comentarios a estos manuales