1-12
be the greatest rule number plus one. If the current greatest rule number is 65534, however, the
system will display an error message and you need to specify a number for the rule.
z
The content of a modified or created rule cannot be identical with the content of any existing rule;
otherwise the rule modification or creation will fail, and the system prompts that the rule already
exists.
z
With the
auto
match order specified, the newly created rules will be inserted in the existent ones by
depth-first principle, but the numbers of the existent rules are unaltered.
Examples
# Create basic ACL 2000 and define rule 1 to deny packets whose source IP addresses are
192.168.0.1.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] acl number 2000
[Sysname-acl-basic-2000] rule 1 deny source 192.168.0.1 0
[Sysname-acl-basic-2000] quit
# Create basic ACL 2001 and define rule 1 to deny packets that are non-tail fragments.
[Sysname] acl number 2001
[Sysname-acl-basic-2001] rule 1 deny fragment
[Sysname-acl-basic-2001] quit
# Create basic ACL 2002 and define rule 1 to deny all packets during the period specified by time range
trname.
[Sysname] acl number 2002
[Sysname-acl-basic-2002] rule 1 deny time-range trname
After completing the above configuration, you can use the
display acl
command to view the
configuration information of the ACLs.
rule (for Advanced ACLs)
Syntax
rule
[
rule-id
] {
deny
|
permit
}
protocol
[
rule-string
]
undo
rule
rule-id
[
destination
|
destination-port
|
dscp
|
fragment
|
icmp-type
|
precedence
|
source
|
source-port
|
time-range
|
tos
]*
View
Advanced ACL view
Parameters
Parameters of the rule command
rule-id
: ACL rule ID, in the range of 0 to 65534.
deny
: Drops the matched packets.
permit
: Permits the matched packets.
Summary of Contents for 5500-EI Series
Page 43: ...2 6 ...
Page 76: ...1 17 ...
Page 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46 ...
Page 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast ...
Page 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23 ...
Page 519: ...iii ...
Page 597: ...2 2 security policy server 192 168 0 1 user name format without domain ...
Page 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static ...
Page 663: ...4 3 Sysname resilient arp interface vlan interface 2 ...
Page 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008 ...
Page 1111: ...ii xmodem get 3 18 ...
Page 1314: ...A 44 Z ...