Chapter 8 ACL Configuration
Note:
Each standard ACL supports up to 127 rules.
If the time range is not configured, the rule is always effective.
4.
In Ethernet interface configuration mode, apply the ACL.
ZXAN(config)#interface gei_1/21/1
ZXAN(config-if)#ip access-group 3 in
5.
(Optional) Query the ACL configuration.
ZXAN(config-if)#show acl 3
acl standard number 3
rule 1 deny 168.1.1.0 0.0.0.255 time-range worktime
rule 2 permit any
6.
(Optional) Query the interface bound with the ACL.
ZXAN(config-if)#show access-list bound
Interface
Direction Type
Status
Acl number/name
gei_1/21/1
in
V4STD
successful
3
– End of Steps –
8.2 Configuring an Extended ACL
This section describes how to configure an extended ACL and apply it to an Ethernet
interface.
Configuration Data
lists the configuration data of the extended ACL.
Table 8-2 Configuration Data of the Extended ACL
Item
Data
ACL number
101
Rule 1
Action: deny
Source address: 192.168.1.0/24
Protocol type: TCP, Telnet
Rule 2
Permit any TCP and telnet traffic
Interface
gei_1/21/1
Steps
1.
In global configuration mode, create an extended ACL.
8-3
SJ-20130520164529-007|2013-06-30 (R1.0)
ZTE Proprietary and Confidential