[Sysname-acl-ethernetframe-4000] display acl 4000
rule 0 d
xcellent-effort source 000d-88f5-97ed ffff-ffff-ffff dest 0011-4301-991e
f
Config
A
A user-defined ACL filters packets by comparing specific bytes in packet headers with specified string.
A user-defined ACL can be n
Configuration prerequisites
T
user-defined ACL rule, you need to define the corresponding time
r
. For information
ion, refer to
C
Ethernet frame ACL 4000, 1 rule
Acl's step is 1
eny cos e
fff-ffff-ffff
uring User-defined
CL
umbered from 5000 to 5999.
o configure a time range-based
anges first
about time range configurat
onfiguring Time Range
.
Configuration procedure
Follow these steps to define a user-defined ACL rule:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Create a user-defined
ined ACL view
ACL and enter
user-def
acl number
acl-number
Required
D fine an ACL rule
rule
[
rule-id
] {
permit
|
deny
}
[
rule-string
rule-mask
offset
] &<1-8>
For information about
Required
e
[
time-range
time-name
]
rule-string
, refer to
ACL
Commands
.
Define a comment for the
ACL rule
rule
rule-id
comment
text
Optional
No description by default
Define a description for
the ACL
description
text
Optional
No description by default
Whe
o
z
z
VPN is enabled on a port, each packet in the switch carries two VLAN tags, which is 8
bytes long.
n configuring a rule that matches specific fields of packets, take the following two items into
acc unt:
If VLAN-VPN is not enabled, each packet in the switch carries one VLAN tag, which is 4 bytes long.
If VLAN-
Note that:
z
You can modify any existent rule of a user-defined ACL. If you modify only the time range and/or
parts of the rule remain the same. If you modify the
rule-string
rule-mask
ver, the new combinations will replace all of the original ones.
action, the unmodified
offset
combinations, howe
44-9