![Alied Telesis GS970M/10 Скачать руководство пользователя страница 878](http://html1.mh-extra.com/html/alied-telesis/gs970m-10/gs970m-10_command-reference-manual_2896773878.webp)
C613-50163-01 Rev C
Command Reference for GS970M Series
878
AlliedWare Plus™ Operating System - Version 5.4.7-0.x
IP
V
4 H
ARDWARE
A
CCESS
C
ONTROL
L
IST
(ACL) C
OMMANDS
(
NAMED
HARDWARE
ACL: IP
PACKET
ENTRY
)
Mode
IPv4 Hardware ACL Configuration (accessed by running the command
)
Default
On an interface controlled by a hardware ACL, any traffic that does not explicitly
match a filter is permitted.
Usage
To use this command, first run the command
and enter the desired access-list name. This changes the prompt to
awplus(config-ip-hw-acl)#.
Then use this command (and the other “named hardware ACL: entry” commands)
to add filter entries. You can add multiple filter entries to an ACL. You can insert a
new filter entry into the middle of an existing list by specifying the appropriate
<source-mac>
The source MAC address to match against. You can specify a
single MAC address, a range (through a mask), the address
learned from DHCP snooping, or any:
any
Match against any source MAC
address.
<source-mac>
The source MAC address to match
against, followed by the mask.
Enter the address in the format
<HHHH.HHHH.HHHH>, where each
H
is a hexadecimal number.
Enter the mask in the format
<HHHH.HHHH.HHHH>, where each
H
is a hexadecimal number. For a
mask, each value is either 0 or F,
where FF = Ignore, and 00 = Match.
dhcpsnooping
Match the source address learned
from the DHCP Snooping binding
database.
<dest-mac>
The destination MAC address to match against. You can specify a
single MAC address, a range (through a mask), or any:
any
Match against any destination MAC
address.
<dest-mac>
The destination MAC address to
match against, followed by the
mask.
Enter the address in the format
<HHHH.HHHH.HHHH>, where each
H
is a hexadecimal number.
Enter the mask in the format
<HHHH.HHHH.HHHH>, where each
H
is a hexadecimal number. For a
mask, each value is either 0 or F,
where FF = Ignore, and 00 = Match.
vlan
<1-4094>
The VLAN to match against. The ACL will match against the
specified ID in the packet’s VLAN tag.
Parameter
Description