
time, for example, QoS needs to be started during peak hours. You can create a time range
and reference the time range in an ACL so that the ACL takes effect in the time range. The
service or function that references the ACL is also started in the specified time range.
10.3 Configuring a Basic ACL
A basic ACL classifies IPv4 packets based on information such as source IP addresses, fragment
flags, and time ranges.
10.3.1 Establishing the Configuration Task
Before configuring a basic ACL, familiarize yourself with the applicable environment, complete
the pre-configuration tasks, and obtain the data required for the configuration. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
Basic ACLs can be referenced by many services and functions such as the routing policy and
traffic classifier. The AR1200-S processes different types of packets based on basic ACL rules.
Basic ACLs are applied to all the IPv4 packets at the network layer and upper layers. Basic ACLs
classify packets based on source IP addresses, fragment flags, and time ranges in the packets.
Pre-configuration Tasks
Before configuring a basic ACL, complete the following task:
l
Setting link layer protocol parameters for interfaces to ensure that the link layer protocol
status on the interfaces is Up
Data Preparation
To configure a basic ACL, you need the following data.
No.
Data
1
(Optional) Name of a time range during which ACL rules take effect
2
Number or name of a basic ACL
3
Source IP address, fragment flag
4
(Optional) Description of a basic ACL
5
(Optional) Description of a basic ACL rule
6
(Optional) Step between ACL rule IDs
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
188