![H3C S5120-SI Series Скачать руководство пользователя страница 496](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174496.webp)
1-2
An ACL can have only one name. Whether to specify a name for an ACL is up to you. After creating an
ACL, you cannot specify a name for it, nor can you change or remove its name.
The name of an ACL must be unique among ACLs.
ACL Match Order
An ACL may consist of multiple rules, which specify different matching criteria. These criteria may have
overlapping or conflicting parts. The match order is for determining how packets should be matched
against the rules.
Two match orders are available for ACLs:
z
config
: Packets are compared against ACL rules in the order the rules are configured.
z
auto
: Packets are compared against ACL rules in the depth-first match order.
The term depth-first match has different meanings for different types of ACLs:
Depth-first match for a basic ACL
The following shows how your device performs depth-first match in a basic ACL:
1) Sort rules by source IP address wildcard and compare packets against the rule configured with
more zeros in the source IP address wildcard.
2) If two rules are present with the same number of zeros in their source IP address wildcards,
compare packets against the rule configured first.
A wildcard mask is in dotted decimal notation. Its binary value 0 means "match" and binary value 1
means "do not care", which contrast with the meanings of the values of a subnet mask. For example, a
wildcard mask of 0.0.0.255 corresponds to a subnet mask of 255.255.255.0.
Depth-first match for an advanced ACL
The following shows how your device performs depth-first match in an advanced ACL:
1) Sort rules by the protocol carried over IP. A rule with no limit to the protocol type (that is, configured
with the
ip
keyword) has the lowest precedence. Rules each of which has a single specified
protocol type are of the same precedence level.
2) If the protocol types have the same precedence, look at the source IP address wildcards. Then,
compare packets against the rule configured with more zeros in the source IP address wildcard.
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...