ZXR10 2900E Series Command Reference
4.13.17 ingress-acl extend rule type-arp
Purpose
This command sets the rule that the extended ingress ACL is used to match ARP
messages.
Command Mode
Extended ingress ACL configuration mode
Syntax
rule
<
1-500
>{
permit
|
deny
}
arp
{<
sender-ipaddr
><
sip-mask
>|
any
}{<
target-ipaddr
><
tip-mask
>|
any
}
Parameter Description
Parameter
Description
<
1-500
>
Rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
arp
This rule only matches ARP message. Non-ARP message
ignores this rule.
<
sender-ipaddr
>
Sender network or host of the ARP package. It is a 32-bit IP
address expressed in dotted decimal notation.
<
sip-mask
>
Source mask and used for source. It is a 32-bit IP address
expressed in dotted decimal notation.
any
(first)
The any keyword is used as the abbreviation of the source 0.0.0.0
and the source mask 0.0.0.0.
<
target-ipaddr
>
Target network or host of the ARP package. It is a 32-bit IP
address expressed in dotted decimal notation.
<
tip-mask
>
Destination mask used for destination. It is a 32-bit IP address
expressed in dotted decimal notation.
any
(second)
The any keyword is used as the abbreviation of the destination
0.0.0.0 and the destination mask 0.0.0.0.
Guidelines
The ARP rule can match ARP packets with sender-specified IP addresses, IP address of
any sender, specified destination IP addresses, or any destination IP address.
4-226
SJ-20130731155059-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential