1.
Check whether ACL rules occupy too many resources.
2.
If ACL rules occupy too many resources, deactivate or delete the unimportant or
temporarily unused ACL configurations, and then configure and enable the protocol
module.
3.13.1 Configuring the Basic ACL for Packet Filtering
This topic is applicable to the scenario where the device needs to classify traffic for packets
according to the source IP address.
Context
The number of a basic ACL is in the range of 2000-2999.
A basic ACL is only defined according to the L3 source IP address for analyzing and processing
data packets.
Procedure
Step 1
(Optional) Set a time range.
Run the
time-range
command to create a time range, which can be used when an ACL rule is
created.
Step 2
Create a basic ACL.
Run the
acl
command to create a basic ACL, and then enter the ACL mode. The number of a
basic ACL can only be in the range of 2000-2999.
Step 3
Configure a basic ACL rule.
In the acl-basic mode, run the
rule
command to create a basic ACL rule. The parameters are as
follows:
l
rule-id
: Indicates the ACL rule ID. To create an ACL rule with a specified ID, use this
parameter.
l
permit
: Indicates the keyword for allowing the data packets that meet related conditions to
pass.
l
deny
: Indicates the keyword for discarding the data packets that meet related conditions.
l
time-range
: Indicates the keyword of the time range during which the ACL rule will be
effective.
Step 4
Activate the ACL.
After an ACL is configured, only an ACL gets generated but it will not be functional. You need
to run other commands to activate the ACL. Some common commands are as follows:
l
Run the
packet-filter
command to activate an ACL.
l
Perform the QoS operation. For details, see
Configuring Traffic Management Based on
----End
Example
To configure that from 00:00 to 12:00 on Fridays, port 0/1/0 on the MA5616 receives only the
packets from 2.2.2.2, and discards the packets from other addresses, do as follows:
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
112