Command Manual - QoS/ACL
Quidway S3500 Series Ethernet Switches
Chapter 1 ACL Commands
Huawei Technologies Proprietary
1-33
Note:
During self-defining flow-template configuration, if you configured any of the three
parameters: dport, sport or tcp-flag, you must configure the ip-protocol parameter at the
same time. Otherwise, the flow template fails to operate.
If you need to define the rule of layer 2 ACL by using parameter tagged or untagged,
you are required to configure the ethernet-protocol parameter in self-defining
flow-template configuration.
A flow template is defined by default, which includes the quintuple of source IP,
destination IP, source TCP/UDP port, destination TCP/UDP port, IP protocol code.
You cannot modify or delete the default flow template, but those you have defined.
For the related command, see
display
flow-template
.
Example
# Define a flow template which classifies traffic by source and destination IP addresses,
source and destination TCP/UDP ports, DSCP domain in the IP packet header.
[Quidway] flow-template user-defined ip-protocol sip dip sport dport dscp
1.3.8 packet-filter
Syntax
I. Command Format in System View
packet-filter
inbound
acl-rule
interface
{
interface-list
|
all
}
undo
packet-filter
inbound
acl-rule
interface
{
interface-list
|
all
}
II. Command Format in Ethernet Port View
packet-filter
inbound
acl-rule
undo
packet-filter
inbound
acl-rule
View
System view/Ethernet Port view
Parameter
acl-rule
: the rule of ACL,
only the rules including these elements defined in template
can be sent to target hardware and referenced for such QoS functions as packet
filtering, traffic policing, priority re-labeling. Otherwise, the rules cannot be activated on
the hardware. The ACL combined mode is following.