Operation Manual – ACL
H3C S5600 Series Ethernet Switches
Chapter 1 ACL Configuration
1-18
II. Network diagram
Figure 1-6
Network diagram for user-defined ACL
III. Configuration procedure
# Define a periodic time range that is active from 8:00 to 18:00 everyday.
<Sysname> system-view
[Sysname] time-range test 8:00 to 18:00 daily
# Define ACL 5000 to deny any ARP packet whose source IP address is 192.168.0.1
from 8:00 to 18:00 everyday. In the ACL rule, 0806 is the ARP protocol number, ffff is
the mask of the rule, 20 is the protocol type field offset of the internally processed
Ethernet frame, c0a80001 is the hexadecimal form of 192.168.0.1, and 36 is the source
IP address field offset of the internally processed ARP packet.
[Sysname] acl number 5000
[Sysname-acl-user-5000] rule 1 deny 0806 ffff 20 c0a80001 ffffffff 36
time-range test
# Apply ACL 5000 on GigabitEthernet 1/0/1.
[Sysname] interface GigabitEthernet1/0/1
[Sysname-GigabitEthernet1/0/1] packet-filter inbound user-group 5000
1.5.5 Example for Applying an ACL to a VLAN
I. Network requirements
PC 1, PC 2 and PC 3 belong to VLAN 10 and connect to the switch through
GigabitEthernet 1/0/1, GigabitEthernet 1/0/2 and GigabitEthernet 1/0/3 respectively.
The IP address of the database server is 192.168.1.2. Apply an ACL to deny packets
from PCs in VLAN 10 to the database server from 8:00 to 18:00 in working days.