2-6
Configuring an Ethernet Frame Header ACL
Ethernet frame header ACLs filter packets based on Layer 2 protocol header fields such as source MAC
address, destination MAC address, 802.1p priority (VLAN priority), and link layer protocol type. They
are numbered in the range 4000 to 4999.
Configuration Prerequisites
If you want to reference a time range to a rule, define it with the
time-range
command first.
Configuration Procedure
Follow these steps to configure an Ethernet frame header ACL:
To do…
Use the command…
Remarks
Enter system view
system-view
––
Create and enter Ethernet
frame header ACL view
acl number
acl-number
[
name
acl-name
] [
match-order
{
auto
|
config
} ]
Required
The default match order is
config
.
If you specify a name for an
IPv4 ACL when creating the
ACL, you can use the
acl
name
acl-name
command to enter
the view of the ACL later.
Create or modify a rule
rule
[
rule-id
] {
deny
|
permit
} [
cos
vlan-pri | dest-mac
dest-addr
dest-mask | lsap lsap-code
lsap-wildcard | source-mac
sour-addr
source-mask
|
time-range
time-range-name | type
type-code
type-wildcard
] *
Required
To create multiple rules, repeat
this step.
Note that the
lsap
keyword is
not supported if the ACL is to
be referenced by a QoS policy
for traffic classification.
Set a rule numbering step
step
step-value
Optional
The default step is 5.
Create an ACL description
description
text
Optional
By default, no IPv4 ACL
description is present.
Create a rule description
rule rule-id comment text
Optional
By default, no rule description
is present.
Note that:
z
You can only modify the existing rules of an ACL that uses the match order of
config
. When
modifying a rule of such an ACL, you may choose to change just some of the settings, in which
case the other settings remain the same.
z
You cannot create a rule with, or modify a rule to have, the same permit/deny statement as an
existing rule in the ACL.
z
When the ACL match order is
auto
, a newly created rule will be inserted among the existing rules in
the depth-first match order. Note that the IDs of the rules still remain the same.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...