
Command Manual (For Soliton) – ACL
H3C S3100 Series Ethernet Switches
Chapter 1 ACL Configuration Commands
1-12
deny
: Drops the matched packets.
permit
: Permits the matched packets.
rule-string
: ACL rule information, which can be a combination of the parameters
described in
Table 1-6
.
Table 1-6
Parameters for basic IPv4 ACL rules
Parameters
Function
Description
source
{
sour-addr
sour-wildcard
|
any
}
Specifies a source
address.
The
sour-addr sour-wildcard
argument specifies a source IP
address in dotted decimal
notation. Setting the wildcard to a
zero indicates a host address.
The
any
keyword indicates any
source IP address.
fragment
Indicates that the rule
applies only to non-tail
fragments.
––
time-range
time-name
Specifies the time range
in which the rule takes
effect.
time-name
: specifies the name of
the time range in which the rule is
active; a string comprising 1 to 32
characters.
Note:
sour-wildcard
is the complement of the wildcard mask of the source subnet mask. For
example, you need to input 0.0.255.255 to specify the subnet mask 255.255.0.0.
II. Parameters of the undo rule command
rule-id
: Rule ID, which must the ID of an existing ACL rule. You can obtain the ID of an
ACL rule by using the
display acl
command.
fragment
: Removes the settings concerning non-tail fragments in the ACL rule.
source
: Removes the settings concerning source address in the ACL rule.
time-range
: Removes the settings concerning time range in the ACL rule.
Note:
When you assign basic ACLs to the hardware for packet filtering, the
fragment
keyword is not supported on a H3C S3100 Series Ethernet switch.