Applying ACLs on Ports
209
Configuration Example
Configure ACL 4000 to deny packets whose 802.1p priority is 3.
<S4200G>
system-view
[4200G]
acl number 4000
[4200G-acl-ethernetframe-4000]
rule deny cos 3
[4200G-acl-ethernetframe-4000]
display acl 4000
Ethernet frame ACL 4000, 1 rule
Acl's step is 1
rule 0 deny cos excellent-effort(0 times matched)
Applying ACLs on
Ports
By applying ACLs on ports, you can enable the packet filtering.
■
You can filter inbound packets on each port. Inbound packets refer to packets
received on a port.
Configuration
Preparation
Before applying an ACL on a port, you must define the ACL first. For the ACL
configuration of time ranges, refer to Defining Basic ACLs, Defining Advanced ACLs,
and Defining Layer 2 ACLs.
Configuration Procedure
The ACLs applied on a port can combinations of different types of ACLs. Table 182
describes the ACL combinations.
cos
vlan-pri
Priority
Defines the
802.1p priority of
the rule
vlan-pri
: VLAN priority, in the range
of 0 to 7
time-range
time-name
Time range
information
Specifies the time
range in which
the rule is active
time-name
: specifies the name of the
time range in which the rule is active;
a string of 1 to 32 characters
type
protocol-type
protocol-mask
Protocol type of
Ethernet frames
Defines the
protocol type of
Ethernet frames
protocol-type
: protocol type
protocol-mask
: protocol type mask
Table 180
Rule information (Continued)
Parameter
Type
Function
Description
Table 181
Apply an ACL on a port
Operation
Command
Description
Enter system view
system-view
-
Enter Ethernet port view
interface
interface-type
interface-number
-
Apply an ACL on a port
packet-filter
inbound
acl-rule
Required
Table 182
Combined application of ACLs
Combination mode
Form of
acl-rule
Apply all rules in an IP type ACL separately
ip-group
acl-number
Apply one rule in an IP type ACL separately
ip-group
acl-number
rule
rule
Apply all rules in a Link type ACL separately
link-group
acl-number
Apply one rule in a Link type ACL separately
link-group
acl-number
rule
rule
Apply one rule in an IP type ACL and one rule
in a Link type ACL simultaneously
ip-group
acl-number
rule
rule
link-group
acl-number
rule
rule
Summary of Contents for 4200G 12-Port
Page 10: ...8 CONTENTS...
Page 14: ...4 ABOUT THIS GUIDE...
Page 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM...
Page 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS...
Page 60: ...46 CHAPTER 9 VLAN CONFIGURATION...
Page 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION...
Page 80: ...66 CHAPTER 13 GVRP CONFIGURATION...
Page 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION...
Page 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT...
Page 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET...
Page 162: ...148 CHAPTER 20 MSTP CONFIGURATION...
Page 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION...
Page 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION...
Page 298: ...284 CHAPTER 33 SNMP CONFIGURATION...
Page 304: ...290 CHAPTER 34 RMON CONFIGURATION...
Page 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES...
Page 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION...
Page 365: ...Information Center Configuration Example 351 S4200G terminal logging...
Page 366: ...352 CHAPTER 39 INFORMATION CENTER...
Page 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING...
Page 384: ...370 CHAPTER 41 Basic System Configuration and Debugging...
Page 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST...
Page 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS...