ZXR10 5250 Series Command Reference
Parameter Description
Parameter
Description
<
1-500
>
Rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
other
This rule is only valid for the packets except IP/ARP. IP/ARP
packet ignores this rule.
ether-type
<
1501-65535
>
This rule is only valid for the packet with specified ether-type value.
Ignore this rule for other messages. The range of ether-type is
1501 to 65535.
dsap-ssap
<
0-65535
>]
This rule is only valid for the packet with specified dsap-ssap
value. Ignore this rule for other messages. The range of
dsap-ssap is 0 to 65535.
cos
<
0-7
>
This rule is only valid for the cos-specified message. Ignore this
rule for other messages. The range of cos is 0 to 7.
<
vlan-id
>
This rule is only valid for messages with the specified VLAN ID.
Ignore this rule for other messages. The rule of VLAN ID is 1
to 4094.
<
vlan-mask
>
Optional VLAN mask. The default value is 0xfff.
<
source-macvlan-id
>
Source MAC address of the transmitted packet.
<
mac-mask
>
Source MAC mask. Compare the result of the source MAC
address & the mask of the packet with the result of <
source-mac
>
& the mask to see whether the ACL rule is matched.
any
The any keyword is used as the abbreviation of source MAC
address 00.00.00.00.00.00 and mask 00.00.00.00.00.00.
<
dest-mac
>
Destination MAC address of the transmitted packet.
<
dmac-mask
>
Destination MAC mask.
any
The any keyword is used as the abbreviation of destination MAC
address 00.00.00.00.00.00 and mask 00.00.00.00.00.00.
Guidelines
Other rules can match packets with ether-type fields, dsap-ssap fields, cos fields, VLAN
fields, specified source MACs, any source MACs, specified destination MACs, or any
destination MACs.
4-272
SJ-20131111172707-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential