294
C
HAPTER
27: ACL C
ONFIGURATION
Note that:
■
If only a periodic time section is defined in a time range, the time range is
active only when the system time is within the defined periodic time section. If
multiple periodic time sections are defined in a time range, the time range is
active only when the system time is within one of the periodic time sections.
■
If only an absolute time section is defined in a time range, the time range is
active only when the system time is within the defined absolute time section. If
multiple absolute time sections are defined in a time range, the time range is
active only when the system time is within one of the absolute time sections.
■
If both a periodic time section and an absolute time section are defined in a
time range, the time range is active only when the periodic time range and the
absolute time range are both matched. Assume that a time range contains an
absolute time section ranging from 00:00 January 1, 2004 to 23:59 December
31, 2004, and a periodic time section ranging from 12:00 to 14:00 on every
Wednesday. This time range is active only when the system time is within the
range from 12:00 to 14:00 on every Wednesday in 2004.
■
If the start time is not specified, the time section starts from 1970/1/1 00:00
and ends on the specified end date. If the end date is not specified, the time
section starts from the specified start date to 2100/12/31 23:59.
Configuration Example
# Define a periodic time range that spans from 8:00 to 18:00 on Monday through
Friday.
<4210> system-view
[4210] time-range test 8:00 to 18:00 working-day
[4210] display time-range test
Current time is 13:27:32 Apr/16/2005 Saturday
Time-range : test ( Inactive )
08:00 to 18:00 working-day
# Define an absolute time range spans from 15:00 1/28/2006 to 15:00 1/28/2008.
<4210> system-view
[4210] time-range test from 15:00 1/28/2006 to 15:00 1/28/2008
[4210] display time-range test
Current time is 13:30:32 Apr/16/2005 Saturday
Time-range : test ( Inactive )
From 15:00 Jan/28/2000 to 15:00 Jan/28/2004
Configuring Basic ACL
A basic ACL filters packets based on their source IP addresses.
A basic ACL can be numbered from 2000 to 2999.
Configuration Prerequisites
■
To configure a time range-based basic ACL rule, you need to create the
corresponding time range first. For information about configuring the time ,
refer to “Configuring a Time Range” on page 293.
■
The source IP addresses based on which the ACL filters packets are determined.
Summary of Contents for Switch 4210 9-Port
Page 22: ...20 CHAPTER 1 CLI CONFIGURATION ...
Page 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT ...
Page 84: ...82 CHAPTER 5 VLAN CONFIGURATION ...
Page 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION ...
Page 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION ...
Page 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION ...
Page 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT ...
Page 234: ...232 CHAPTER 17 802 1X CONFIGURATION ...
Page 246: ...244 CHAPTER 20 AAA OVERVIEW ...
Page 270: ...268 CHAPTER 21 AAA CONFIGURATION ...
Page 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION ...
Page 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION ...
Page 340: ...338 CHAPTER 30 CLUSTER ...
Page 362: ...360 CHAPTER 33 SNMP CONFIGURATION ...
Page 368: ...366 CHAPTER 34 RMON CONFIGURATION ...
Page 450: ...448 CHAPTER 39 TFTP CONFIGURATION ...
Page 451: ......
Page 452: ...450 CHAPTER 39 TFTP CONFIGURATION ...
Page 470: ...468 CHAPTER 40 INFORMATION CENTER ...
Page 496: ...494 CHAPTER 44 DEVICE MANAGEMENT ...