2-3
To do…
Use the command…
Remarks
Enter system view
system-view
––
Create and enter basic IPv4
ACL view
acl number
acl-number
[
name
acl-name
] [
match-order
{
auto
|
config
} ]
Required
The default match order is
config
.
If you specify a name for an IPv4
ACL when creating the ACL, you
can use the
acl
name
acl-name
command to enter the view of
the ACL later.
Create or modify a rule
rule
[
rule-id
] {
deny
|
permit
}
[
fragment
|
logging
|
source
{
sour-addr sour-wildcard
|
any
} |
time-range
time-range-name
|
vpn-instance
vpn-instance-name
] *
Required
To create multiple rules, repeat
this step.
Note that the
logging
and
vpn-instance
keywords are not
supported if the ACL is to be
referenced by a QoS policy for
traffic classification.
Set a rule numbering step
step
step-value
Optional
The default step is 5.
Create an IPv4 ACL
description
description
text
Optional
By default, no IPv4 ACL
description is present.
Create a rule description
rule rule-id comment text
Optional
By default, no rule description is
present.
Note that:
z
You can only modify the existing rules of an ACL that uses the match order of
config
. When
modifying a rule of such an ACL, you may choose to change just some of the settings, in which
case the other settings remain the same.
z
You cannot create a rule with, or modify a rule to have, the same permit/deny statement as an
existing rule in the ACL.
z
When the ACL match order is
auto
, a newly created rule will be inserted among the existing rules in
the depth-first match order. Note that the IDs of the rules still remain the same.
z
You can modify the match order of an ACL with the
acl number
acl-number
[
name acl-name
]
match-order
{
auto
|
config
} command but only when it does not contain any rules.
z
The rule specified in the
rule comment
command must have existed.
Configuration Examples
# Create IPv4 ACL 2000 to deny the packets with source address 1.1.1.1 to pass.
<Sysname> system-view
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...