access-list
Defines a standard or extended IP access list. The extended access list enables you to specify a destination address or host, precedence, and type of service. This command imposes an implicit last rule of "deny ip any any" to deny all routes that do not match previous rules in the access list. The no version removes the IP access list, the specified entry in an access list, or the log for a specified entry.
Standard IP access list:
access-list accessListName { permit | deny }
{ srcIP srcWildIp | [ host ] srcIPHost | any } [ log ]no access-list accessListName [ { permit | deny }
{ srcIP srcWildIp | [ host ] srcIPHost | any } [ log ] ]access-list accessListName { permit | deny } ip { srcIP srcWildIp |
host srcIPHost | any } { dstIP dstWildIp | host dstIPHost | any } [ log ]no access-list accessListName [ { permit | deny } ip { srcIP srcWildIp |
host srcIPHost | any } { dstIP dstWildIp | host dstIPHost | any } [ log ] ]
- accessListNameString of up to 32 alphanumeric characters
- permitPermits access if the conditions are matched
- denyDenies access if the conditions are matched
- srcIPSource IP address from which the packet is being sent
- srcWildIpWildcard mask IP address
- hostIdentifies the address as a host
- srcIPHostSource host IP address; assumes a wildcard mask of 0
- anyCreates an address of 0.0.0.0 with a wildcard mask of 255.255.255.255
- dstIPDestination IP address
- dstWildIpWildcard mask IP address for destination
- dstIPHostDestination host IP address to which the packet is being sent
- logLogs an Info event into the ipAccessList log whenever the access-list rule is matched
Global Configuration
Release Information Command introduced before JUNOSe Release 7.1.0.