![H3C S3100 Series Скачать руководство пользователя страница 552](http://html1.mh-extra.com/html/h3c/s3100-series/s3100-series_command-manual_3591810552.webp)
Command Manual (For Soliton) – ACL
H3C S3100 Series Ethernet Switches
Chapter 1 ACL Configuration Commands
1-13
Description
Use the
rule
command to define an ACL rule.
Use the
undo rule
command to remove an ACL rule or specified settings of an ACL
rule.
To remove an ACL rule using the
undo rule
command, you need to provide the ID of
the ACL rule. If no other arguments are specified, the entire ACL rule is removed.
Otherwise, only the specified information of the ACL rule is removed.
Note that:
z
With the
config
match order specified for the basic ACL, you can modify any
existent rule. The unmodified part of the rule remains. With the
auto
match order
specified for the basic ACL, you cannot modify any existent rule; otherwise the
system prompts error information.
z
If you do not specify the
rule-id
argument when creating an ACL rule, the rule will
be numbered automatically. If the ACL has no rules, the rule is numbered 0;
otherwise, the number of the rule will be the greatest rule number plus one. If the
current greatest rule number is 65534, however, the system will display an error
message and you need to specify a number for the rule.
z
The content of a modified or created rule cannot be identical with the content of
any existing rule; otherwise the rule modification or creation will fail, and the
system prompts that the rule already exists.
z
With the
auto
match order specified, the newly created rules will be inserted in the
existent ones by depth-first principle, but the numbers of the existent rules are
unaltered.
Examples
# Create basic ACL 2000 and define rule 1 to deny packets whose source IP addresses
are 192.168.0.1.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] acl number 2000
[Sysname-acl-basic-2000] rule 1 deny source 192.168.0.1 0
[Sysname-acl-basic-2000] quit
# Create basic ACL 2001 and define rule 1 to deny packets that are non-tail fragments.
[Sysname] acl number 2001
[Sysname-acl-basic-2001] rule 1 deny fragment
[Sysname-acl-basic-2001] quit
# Create basic ACL 2002 and define rule 1 to deny all packets during the period
specified by time range trname.
[Sysname] acl number 2002
[Sysname-acl-basic-2002] rule 1 deny time-range trname