Re: RE: tcp-syn command

From: gladston@br.ibm.com
Date: Tue Jun 21 2005 - 21:58:53 GMT-3


Oh, thanks

I was looking for a command like that some weeks ago and gave up.

Certainly I would miss those related points before reading your email.

(why Cisco do that?)

R1(config)#access-list 101 permit tcp a a ?
  ack Match on the ACK bit
  dscp Match packets with given dscp value
  eq Match only packets on a given port number
  established Match established connections
  fin Match on the FIN bit
  fragments Check non-initial fragments
  gt Match only packets with a greater port number
  log Log matches against this entry
  log-input Log matches against this entry, including input interface
  lt Match only packets with a lower port number
  neq Match only packets not on a given port number
  precedence Match packets with given precedence value
  psh Match on the PSH bit
  range Match only packets in the range of port numbers
  rst Match on the RST bit
  syn Match on the SYN bit
  time-range Specify a time-range
  tos Match packets with given TOS value
  urg Match on the URG bit



This archive was generated by hypermail 2.1.4 : Wed Jul 06 2005 - 14:43:42 GMT-3