Chapter 4 Service Configuration
Command Mode
Layer 2 ingress ACL configuration mode
Syntax
rule
<
1-500
>{
permit
|
deny
}
other
{[
ether-type
<
1501-65535
>|
dsap-ssap
<
0-65535
>][
co
s
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]}
Parameter Description
Parameter
Description
<
1-500
>
Rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
other
This rule is only valid for the packets except IP/ARP. IP/ARP
packet ignores this rule.
ether-type
<
1501-65535
>
This rule is only valid for the packet with specified ether-type value.
Ignore this rule for other messages. The range of ether-type is
1501 to 65535. Of which 2048, 2054 and 34525 respectively
corresponds to 0x0800, 0x0806 and 0x86DD.
dsap-ssap
<
0-65535
>
This rule is only valid for the packet with specified dsap-ssap
value. Ignore this rule for other messages. The range of
dsap-ssap is 0 to 65535.
cos
<
0-7
>
This rule is only valid for the cos-specified message. Ignore this
rule for other messages. The range of cos is 0 to 7.
<
vlan-id
>
This rule is only valid for messages with the specified VLAN ID.
Ignore this rule for other messages. The rule of VLAN ID is 1
to 4094.
<
vlan-mask
>
Optional VLAN mask. The default value is 0xfff.
<
source-mac
>
Source MAC address of the transmitted packet.
<
smac-mask
>
Source MAC mask.
any
(first)
The any keyword is used as the abbreviation of the source MAC
address 00.00.00.00.00.00 and the mask 00.00.00.00.00.00.
<
dest-mac
>
Destination MAC address of the transmitted packet.
<
dmac-mask
>
Destination MAC mask.
any
(second)
The any keyword is used as the abbreviation of the destination
MAC address 00.00.00.00.00.00 and the mask 00.00.00.00.00.00.
4-231
SJ-20131111172707-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential