T2700G-28TQ
JetStream 28-Port Gigabit Stackable L2+ Managed Switch CLI Guide
209
source-ip-mask
—— The source IP address mask. It is required if you typed the
source IP address.
destination-ip
—— The destination IP address contained in the rule.
destination-ip-mask
—— The destination IP address mask. It is required if you
typed the destination IP address.
time-segment
—— The time-range for the rule to take effect. By default, it is not
limited.
dscp
—— Specify the dscp value, ranging from 0 to 63.
s-port
—— The source port number.
d-port
—— The destination port number.
tcpflag
—— Specify the flag value when using TCP protocol.
protocol
—— Configure the value of the matching protocol.
tos
—— Enter the IP ToS contained in the rule.
pre
—— Enter the IP Precedence contained in the rule.
Command Mode
Global Configuration Mode
Example
Create an Extended-IP ACL whose ID is 2220, and add Rule 10 for it. In the rule,
the source IP address is 192.168.0.100, the source IP address mask is
255.255.255.0, the time-range for the rule to take effect is tSeg1, and the
packets match this rule will be forwarded by the switch:
T2700G-28TQ(config)#access-list create
2220
T2700G-28TQ(config)#access-list extended
2220
rule
10 permit
sip
192.168.0.100
smask
255.255.255.0
tseg
tSeg1
rule
Description
The
rule
command is used to configure MAC ACL rule. To delete the
corresponding rule, please use
no rule
command.
Syntax
rule
rule-id
{deny | permit} [
smac
source-mac
smask
source-mac-mask
]
[
dmac
destination-mac
dmask
destination-mac-mask
] [
type
ethernet-type
] [
pri
user-pri
] [
tseg
time-segment
]