ZXR10 2900E Series Command Reference
4.13.38 config ingress-acl global
Purpose
This command enters the global ingress ACL instance and configures the instance.
Command Mode
Global configuration mode
Syntax
config ingress-acl global
4.13.39 ingress-acl global rule type-ip-protocol
Purpose
This command sets the rule that the global ingress ACL matches the packet with
IPv4-specified field.
Command Mode
Global ingress ACL configuration mode
Syntax
rule
<
1-16
>{
permit
|
deny
}
port
{<
1-28
>|
any
}<
ip-protocol
>{<
source-ipaddr
><
sip-mask
>|
an
y
}{<
destination-ipaddr
><
dip-mask
>|
any
}[
dscp
<
0-63
>][
fragment
][
cos
<
0-7
>][<
vlan-id
>[<
vla
n-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]
Parameter Description
Parameter
Description
<
1-16
>
Global rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
<
1-28
>
Binds the global rule to a port. Different devices have different
port number ranges. In the syntax, the 2928E device is used as
an example.
any
(first)
Binds the global rule to all ports.
<
ip-protocol
>
This rule is only valid for messages with the specified IP protocol
field. Ignore this rule for other messages. The range of IP protocol
field value is 0 to 255.
4-248
SJ-20130731155059-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential