Operation Manual - QoS/ACL
Quidway S3000-EI Series Ethernet Switches
Chapter 1 ACL Configuration
Huawei Technologies Proprietary
1-5
Table 1-4
Defining the basic ACL
Operation
Command
Enter basic ACL view(from
system view)
acl
{
number acl-number | name acl-name
basic
}
[
match-order
{
config
|
auto
} ]
add a sub-item to the ACL(from
basic ACL view)
rule
[
rule-id
] {
permit
|
deny
} [
source
{
source-addr wildcard
|
any
} |
fragment
|
time-range
name
]*
delete a sub-item from the
ACL(from basic ACL view)
undo rule rule-id
[
source
|
fragment
|
time-range
]*
Delete one ACL or all the
ACL(from system view)
undo acl
{
number acl-number
|
name
acl-name | all
}
II. Defining the advanced ACL
The rules of the classification for advanced ACL are defined on the basis of the
attributes such as source and destination IP address, the TCP or UDP port number in
use and packet priority to process the data packets. The advanced ACL supports the
analyses of three kinds of packet priorities, ToS (Type of Service), IP and DSCP
priorities.
You can use the following command to define advanced ACL.
Perform the following configuration in corresponding view.
Table 1-5
Defining the advanced ACL
Operation
Command
Enter advanced ACL
view(from system view)
acl
{
number acl-number | name acl-name
advanced
}
[
match-order
{
config
|
auto
} ]
Add a sub-item to the
ACL(from advanced ACL
view)
rule
[
rule-id
] {
permit
|
deny
}
protocol
[
source
{
source-addr wildcard
|
any
} ] [
destination
{
dest-addr dest-mask
|
any
} ] [
source-port operator
port1
[
port2
] ] [
destination-port operator port1
[
port2
] ] [
icmp-type type code
] [
established
]
[ [
precedence
precedence
|
tos
tos
]* |
dscp
dscp
]
[
fragment
] [
time-range
name
]
Delete a sub-item from
the ACL(from advanced
ACL view)
undo rule rule-id
[
destination
|
destination-port
|
dscp
|
fragment
|
icmp-type
|
precedence
|
source
|
source-port
|
time-range
|
tos
]*
Delete one ACL or all the
ACL(from system view)
undo acl
{
number acl-number | name acl-name | all
}
The advanced ACL is identified with the numbers ranging from 3000 to 3999.
Note that, the
port1
and
port2
in the above command specify the TCP or UDP ports
used by various high-layer applications. For some common port numbers, you can use