Configuration Guide
Access
Control List Configuration
Note
ACL80 support matching against Ethernet packets, 803.3 SNAP packets,
and 802.311c packets. If the value for matching DSAP to the cnt1 field is set
to AAAA03, it indicates to match the 803.3 SNAP packets. If the value is set
to E0E003, it indicates to match the 803.311c packets. This field cannot be
set to match Ethernet packets.
Configuration note:
The ACL180 has only 16 bytes for matching. If the 16 bytes are used, no
fields other than the 16 bytes can be matched. For example:
Ruijie(config)#
expert access-list advanced
name
Ruijie(config-exp-dacl)#
permit
11223344556677889900aabbccd
deeff ffffffffffffffffffffffffffffffff 50
If you use the following command to add another ACE:
Ruijie(config-exp-dacl)#permit 11223344556677889900aabbccd
deeff ffffffffffffffffffffffffffffffff 54
The configuration will fail because the 16 bytes are used by the first ACE. To
match the second ACE, you must firstly delete the first ACE.
Configuring TCP Flag Filtering Control
The TCP Flag filtering feature provides a flexible mechanism. At present, TCP Flag filtering control
supports the match-all option. Namely, when the TCP Flags in a received message exactly match
those defined in the ACL table entry, the message will be checked by the ACL rule. A user can define
any combination of TCP Flags to filter some messages with specific TCP Flags.
For example,
permit tcp any any match-all rst
Allow the messages with a TCP Flag RST set and 0 in other positions to pass
Note
When the protocol number of the naming ACL and numerical value
configuration is TCP, you can select to configure this filtering feature. MAC
extended and IP standard ones do not have this function.
Please configure a TCP Flag by following these steps:
Command
Function
Ruijie(config)#
ip access-list
extended
{ id |
name
}
Enter the access list configuration mode
Ruijie(config-ext-nacl)# [
sn
] [
permit
|
deny
]
tcp
source
source-wildcard
[
operator port
[port]
]
destination
destination-wildcard
[
operator port
[ port ]
] [
match-all
flag-name
][
precedence
precedence
]
Add table entries for ACL. For details about
commands, please see command reference.
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...