Chapter 4 Service Configuration
Command Mode
Layer 2 ingress ACL configuration mode
Syntax
rule
<
1-500
>{
permit
|
deny
}
ip
{[
cos
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-ma
sk
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]}
Parameter Description
Parameter
Description
<
1-500
>
Rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
ip
This rule is only valid for IP packet. Non-IP packet ignores this
rule.
cos
<
0-7
>
This rule is only valid for the cos-specified message. Ignore this
rule for other messages. The range of cos is 0 to 7.
<
vlan-id
>
This rule is only valid for messages with the specified VLAN ID.
Ignore this rule for other messages. The rule of VLAN ID is 1
to 4094.
<
vlan-mask
>
Optional VLAN mask. The default value is 0xfff.
<
source-mac
>
Source MAC address of the transmitted packet.
<
smac-mask
>
Source MAC mask.
any
(first)
The any keyword is used as the abbreviation of the source MAC
address 00.00.00.00.00.00 and the mask 00.00.00.00.00.00.
<
dest-mac
>
Destination MAC address of the transmitted packet.
<
dmac-mask
>
Destination MAC mask.
any
(second)
The any keyword is used as the abbreviation of the destination
MAC address 00.00.00.00.00.00 and the mask 00.00.00.00.00.00.
Guidelines
The IP rule can match IPv4 packets with cos fields, VLAN fields, specified source MAC,
any source MAC, specified destination MAC, or any destination MAC.
4.13.21 ingress-acl link rule type-arp
Purpose
This command sets the rule that the layer–2 ingress ACL matches ARP packets.
4-229
SJ-20131111172707-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential