Apply ACL rules on the
packet-filter
{
inbound
port
outbound
}
acl-rule
to
ACL Commands
.
|
Required
For information about
acl-rule
, refer
Configuration example
# Apply ACL 2000 on Ethernet 1/0/1 to filter inbound packets.
<Sysname> system-view
[S
name] interface Ethernet 1/0/1
ys
ys
Apply ng ACL Rules to Ports in a VLAN
in a VLAN, you can add filtering of packets on all the ports in the VLAN.
[S
name-Ethernet1/0/1] packet-filter inbound ip-group 2000
i
By applying ACL rules to ports
The ACL rules are only applied to ports that are in the VLAN at the time the
packet-filter vlan
command is executed. In other words:
for packet filtering.
z
A port leaving the VLAN later will ke
for packet filteri
z
A port joining the VLAN later will not use the ACL rules
ep using the ACL rules
ng.
Co
Before applying ACL rules to ports in a VLAN, you need to define the related
rmation
bout defining an ACL, refer to
Configuring Basic ACL
nfiguration prerequisites
ACLs. For info
a
,
Configuring Advanced ACL
,
Configuring Layer 2
ACL
,
Configuring User-defined ACL
and
Configuring IPv6 ACL
.
C
y ACL rules to ports in a VLAN:
onfiguration procedure
Follow these steps to appl
To do...
Use the command...
Remarks
Enter system view
system-view
—
Apply ACL
rts in a
VLAN
packet-filter
vlan vlan-id
{
inbound
acl-rule
Required
For information
le
,
refer to
ACL Commands
.
rules to po
|
outbound
}
about
acl-ru
Configuration example
#
of VL
er packets.
<Sysname> system-view
[Sysname] packet-filter vlan 1 inbound ip-group 2000
Apply ACL 2000 to all ports
AN 1 in the inbound direction to filt
44-13