![H3C S5120-SI Series Operation Manual Download Page 505](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174505.webp)
3-1
3
ACL Application for Packet Filtering
When applying an ACL for packet filtering, go to these sections for information you are interested in:
z
Filtering Ethernet Frames
z
Filtering IPv4 Packets
z
ACL Application Example
You can apply an ACL to the inbound direction of an interface to filter received packets such as Ethernet
frames and IPv4 packets.
Filtering Ethernet Frames
Follow these steps to apply an Ethernet frame header ACL to an interface to filter Ethernet frames:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface interface-type
interface-number
—
Apply an Ethernet frame
header ACL to the interface to
filter Ethernet frames
packet-filter
{
acl-number |
name
acl-name
}
inbound
Required
By default, an interface does
not filter Ethernet frames.
Filtering IPv4 Packets
Follow these steps to apply an ACL to an interface to filter IPv4 packets:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface interface-type
interface-number
—
Apply a basic or advanced ACL
to the interface to filter IPv4
packets
packet-filter
{
acl-number
|
name
acl-name
}
inbound
Required
By default, an interface does
not filter IPv4 packets.
ACL Application Example
Network requirements
As shown in
Figure 3-1
, apply an ACL to the inbound direction of interface GigabitEthernet 1/0/1 on
Device A so that the interface denies IPv4 packets sourced from Host A from 8:00 to 18:00 everyday.