Operation Manual – ACL
H3C S3610&S5510 Series Ethernet Switches
Chapter 4 Flow Template Configuration
4-3
Note:
z
The user-defined ACLs are used in conjunction with the extended user-defined flow
template. When a port applies the extended flow template, you cannot apply policies
including the basic and advanced ACLs on the port.
z
The offset range of a user-defined extended flow template must cover the offset
range of the cooperating user-defined ACL; otherwise, the user-defined ACL cannot
be applied successfully.
z
Before applying a user-defined template on a port, make sure the user-defined
template is already configured. A port can be configured with only one flow
template.
z
Before you can apply a flow template on a port, make sure the following functions
are disabled on the port: 802.1x, cluster (NDP, NTDP, HABP, and Cluster), DHCP
Snooping, port isolation, MAC+IP+port binding, selective QinQ, and voice VLAN.
And also, you are not recommended to use these functions after you apply a flow
template on the port.
The S3610 and S5510 Series Ethernet Switches support up to two user-defined flow
templates each. Note that the total length of all the elements in a basic flow template
must be less than 16 bytes; otherwise, you will see an error message when applying
the flow template.
lists the lengths of all elements.
Table 4-1
Lengths of various elements
Element
Description
Length (in bytes)
customer-cos
Customer 802.1p COS field
1
customer-vlan-id
Customer VLAN ID field
6
dip
Destination IP address field in IP head
0
dipv6
Destination IPv6 address field in IPv6
head
10
dmac
Destination MAC address field in
ethernet packet head
6
dport
Destination port field
2
ethernet-protocol
The protocol type field in ethernet
packet head
4
dscp
DSCP field in IP head
ip-precedence
Precedence field in IP head
tos
ToS field in IP head
1
fragments
Fragments field in IP head
0
icmp-code
ICMP code field
2