l
To define matching rules based on the DSCP priority of IP packets, run:
if-match
dscp
dscp-value
&<1-8>
l
To define matching rules based on the IP priority of IP packets, run:
if-match ip-precedence
ip-precedence-value
&<1-8>
NOTE
In a traffic classifier where the relationship between rules is AND, the
if-match dscp
and
if-match ip-
precedence
commands cannot be used simultaneously.
l
To define matching rules based on the Layer 3 protocol type, run:
if-match protocol
{
ip
|
ipv6
}
l
To define matching rules based on the SYN Flag field of TCP packets, run:
if-match tcp
syn-flag
{
syn-flag-value
|
ack
|
fin
|
psh
|
rst
|
syn
|
urg
}
----End
Creating a Traffic Classifier Based on an ACL
After traffic classification based on an ACL is configured, the S3700 classifies packets based
on the ACL.
Context
The S3700 can use an ACL to classify packets based on the IP quintuple.
The S3700 supports basic ACLs, Layer 2 ACLs, user-defined ACLs and advanced ACLs:
l
Basic ACLs are used to classify data packets based on the source IP address, fragmentation
flag, and time segment of packets.
l
Advanced ACLs are used to classify and define data packets based on the source IP address,
destination IP address, source port number, destination port number, fragmentation flag,
time segment, and protocol type of packets.
l
Layer 2 ACLs are used to classify data packets based on the source MAC address and
destination MAC address of packets.
l
User-defined ACLs process data packets according to the rules defined by users.
Procedure
l
Creating a traffic classifier based on a basic ACL
1.
Run:
system-view
The system view is displayed.
2.
Run:
acl
[
ipv6
]
basic-acl-number
A basic ACL is created and the ACL view is displayed.
Or, run:
acl
[
ipv6
]
name
acl-name
basic
A named ACL is created and ACL view is displayed.
S3700HI Ethernet Switches
Configuration Guide - QoS
1 Class-based QoS Configuration
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
13