
l
Run the
step
command to change the step value.
l
Run the
rule
command with
rule-id
specified to add a new rule between existing rules when
the configuration order is used.
10.3.5 Applying a Basic ACL
A basic ACL can be applied to some services and functions to classify packets.
Prerequisites
A basic ACL has been created and rules have been configured in the basic ACL.
Context
A basic ACL can be applied to the following services and functions:
l
Traffic classifier
l
Blacklist for local attack defense
l
Route filtering
l
OSPF LSA filtering
l
IP multicast
l
Limiting access to an FTP or TFTP server
l
Firewall
l
NAT
l
Packet filtering on an interface
Procedure
l
Apply a basic ACL to a traffic classifier.
To provide differentiated services based on packet information, configure traffic classifiers.
Basic ACLs can be referenced by traffic classifiers to define rules for classifying traffic.
For details, see Configuring a Traffic Classifier.
l
Apply a basic ACL to add specified users to the blacklist for local attack defense.
A blacklist is a set of unauthorized users. The AR1200-S uses basic ACLs to add users with
a specific characteristic to a blacklist and discards the packets from the users in the blacklist.
For details, see
9.4.3 (Optional) Configuring a Blacklist
.
l
Apply a basic ACL to route filtering.
You can configure route filtering for the Routing Information Protocol (RIP), Open Shortest
Path First (OSPF), Intermediate System-to-Intermediate System (IS-IS), and Multiprotocol
Border Gateway Protocol (MBGP), and set conditions for filtering routes of these protocols.
The routes that do not meet the conditions are not added to the routing table or advertised.
The AR1200-S uses basic ACLs to set filtering conditions so that route filtering is
implemented. For details, see Configuration Guide - IP Routing.
l
Apply a basic ACL to OSPF LSA filtering.
In special network environments, OSPF features need to be configured and performance
of the OSPF network needs to be improved. When multiple links exist between two routers,
you can filter outgoing LSAs on the local router. This can reduce the unnecessary
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
192