
Pre-configuration Tasks
Before configuring a Layer 2 ACL, complete the following task:
l
Connecting interfaces and setting physical parameters for the interfaces to ensure that the
physical status of the interfaces is Up
Data Preparation
To configure a Layer 2 ACL, you need the following data.
No.
Data
1
(Optional) Name of a time range during which ACL rules take effect
2
Number or name of a Layer 2 ACL
3
Source MAC address, destination MAC address, Layer 2 protocol type, and VLAN
ID or 802.1p priority
4
(Optional) Description of a Layer 2 ACL
5
(Optional) Description of a Layer 2 ACL rule
6
(Optional) Step value between Layer 2 ACL rule IDs
10.5.2 (Optional) Creating a Time Range for a Layer 2 ACL
To make a Layer 2 ACL take effect during a specified period of time, create a time range and
reference the time range in the Layer 2 ACL. If no time range is specified for the ACL, the ACL
remains effective until it is deleted or the rules of the ACL are deleted.
Context
Some services or functions that reference Layer 2 ACLs need to be started during a specified
period of time, for example, QoS needs to be started during peak hours. You can create a time
range and reference the time range in a Layer 2 ACL so that the Layer 2 ACL takes effect in the
time range. The service or function that references the Layer 2 ACL is also started in the specified
time range.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
time-range
time-name
{
start-time
to
end-time
days
|
from
time1
date1
[
to
time2
date2
] }
A time range is created.
To configure multiple time ranges with the same name on the AR1200-S, run the preceding
command with the same value of
time-name
multiple times.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
203