3Com Switch 8800 Configuration Guide
Chapter 34 Logon User ACL Control Configuration
34-2
Operation
Command
Delete a sub-rule (basic ACL
view)
undo rule rule
-
id
[
source
] [
fragment
]
[
time-range
]
Delete an ACL or all ACLs
(system view)
undo acl
{
number acl
-
number
|
name acl
-
name
|
all
}
Enter advanced ACL view from
system view
acl
{
number acl
-
number
|
name
acl
-
name
advanced
}
[
match-order
{
config
|
auto
} ]
Define sub-rule( advanced
ACL view)
rule
[
rule
-
id
] {
permit
|
deny
}
protocol
[
source
{
source
-
addr
wildcard
|
any
} ] [
destination
{
dest
-
addr
wildcard
|
any
} ] [
source-port
operator
port1
[
port2
] ] [
destination-port
operator
port1
[
port2
] ] [
icmp-type type
code
]
[
established
] [ [
precedence
precedence
|
tos
tos
]* |
dscp
dscp
] [
fragment
] [
time-range
name
] [
vpn-instance instance
-
name
]
Delete a sub-rule(advanced
ACL view )
undo rule rule
-
id
[
source
|
destination
|
source-port
|
destination-port
|
icmp-type
|
precedence
|
tos
|
dscp
|
fragment
|
time-range
|
vpn-instance
]*
Delete an ACL or all ACLs
(system view)
undo acl
{
number acl
-
number
|
name acl
-
name
|
all
}
You can define multiple rules for an ACL by using the
rule
command several times.
34.2.2 Importing ACL
You can import a defined ACL in user interface view to achieve ACL control.
Perform the following configurations respectively in system view and user interface
view.
Table 34-2
Import ACL
Operation
Command
Enter user interface view (system view)
user-interface
[
type
]
first
-
number
Import the ACL (user interface view)
acl
acl
-
number
{
inbound
|
outbound
}
See the Command Manual for details about these commands.
Note:
Currently the ACL control function of TELNET user can reference to the number-based
ACLs and advanced ACLs.