VN/UN564:1VN/UN5674
LgvUvtgco" N4" Ocpcigf" Uykvej" ENK" Iwkfg
150
source-ip
—— The source IP address contained in the rule.
source-ip-mask
—— The source IP address mask. It is required if you typed the
source IP address.
destination-ip
—— The destination IP address contained in the rule.
destination-ip-mask
—— The destination IP address mask. It is required if you
typed the destination IP address.
time-segment
—— The time-range for the rule to take effect. By default, it is not
limited.
frag —— Enable/Disable Fragment. By default, it is disabled. If Fragment is
enabled, this rule will process all the fragments and the last piece of fragment
will be always forwarded.
dscp
—— Specify the dscp value, ranging from 0 to 63.
s-port
—— The source port number.
d-port
—— The destination port number.
tcpflag
—— Specify the flag value when using TCP protocol.
protocol
—— Configure the value of the matching protocol.
icmptype
—— Configure the predefined ICMP type.
icmpcode
—— Configure the predefined ICMP code.
tos
—— Enter the IP ToS contained in the rule.
pri
—— Enter the IP Precedence contained in the rule.
Eqoocpf"Oqfg"
Global Configuration Mode
Gzcorng"
Create an Extended-IP ACL whose ID is 220, and add Rule 10 for it. In the rule,
the source IP address is 192.168.0.100, the source IP address mask is
255.255.255.0, the time-range for the rule to take effect is tSeg1, and the
packets match this rule will be forwarded by the switch:
VN/UN564:*%ceeguu/nkuv"etgcvg"
220
"
VN/UN564:*%ceeguu/nkuv"gzvgpfgf"
220
twng"
10 permit
ukr
192.168.0.100
uocum
255.255.255.0
vugi
tSeg1