ZXR10 5250 Series Command Reference
Guidelines
ARP rule can match sender-specified IP, any sender IP, destination-specified IP,
any destination IP, cos field, VLAN field, source-specified MAC, any source MAC,
destination-specified MAC and any destination MAC. The rule can be bound to one or all
ports.
4.13.44 ingress-acl global rule type-any
Purpose
This command sets the rule that the global ingress ACL matches the non-IPv6 packet.
Command Mode
Global ingress ACL configuration mode
Syntax
rule
<
1-500
>{
permit
|
deny
}
port
{<
1-28
>|
any
}
any
{[
ether-type
<
1501-65535
>][
cos
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]}
Parameter Description
Parameter
Description
<
1-16
>
Global rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
<
1-28
>
Binds the global rule to a port. Different devices have different
port number ranges. In the syntax, the 5250-28TC device is used
as an example.
any
(first)
Binds the global rule to all ports.
any
(second)
This rule only matches non-IPv6 packet. The IPv6 packet ignores
this rule.
ether-type
<
1501-65535
>
This rule is only valid for the packet with specified ether-type.
Other packets ignore this rule. The range of ether-type is 1501
to 65535.
cos
<
0-7
>
This rule is only valid for the cos-specified message. Ignore this
rule for other messages. The range of cos is 0 to 7.
<
vlan-id
>
This rule is only valid for messages with the specified VLAN ID.
Ignore this rule for other messages. The rule of VLAN ID is 1
to 4094.
<
vlan-mask
>
Optional VLAN mask. The default value is 0xfff.
4-258
SJ-20131111172707-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential