Forum Discussion

Songseajoon_222's avatar
Songseajoon_222
Icon for Nimbostratus rankNimbostratus
Mar 28, 2016

Creating ACL using the CLI

F5 Big-IP APM 11.5.3

 

I would like to set the ACL, as the table below. Geotinde loading each Port to each IP,

 

The F5 function IP does not divided into subnets, The port is also called meaningless start port ~ end port.

 

In other words, for one must enter the port of IP as per one of the ongoing

 

To be one of the input port of per one IP to continue

 

(For example: dst.IP = 1.1.1.31 // dst.port = 80, dst.IP = 1.1.1.131 // dst.port 8080)

 

Have there any way that you can apply a little more quickly?

 

Using the CLI method seems to be better.

 

 

3 Replies

  • Hi,

    you can try something like this from cli:

    tmos create net packet-filter pf_cli order 1 action accept logging enabled vlan vlan_name rule '(( ip proto TCP or ip6 proto TCP )  ) and ( dst host 1.1.1.31 or dst host 1.1.1.32 or dst host 1.1.1.34) and (dst port 80 or dst port 443)'