![H3C S5120-SI Series Скачать руководство пользователя страница 502](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174502.webp)
2-4
To do…
Use the command…
Remarks
Create or modify a rule
rule
[
rule-id
] {
deny
|
permit
}
protocol
[ {
ack
ack-value
|
fin
fin-value
|
psh
psh-value
|
rst
rst-value
|
syn
syn-value
|
urg
urg-value
} * |
destination
{
dest-addr dest-wildcard
|
any
}
|
destination-port operator
port1
[
port2
] |
dscp
dscp |
fragment
|
icmp-type
{
icmp-type
icmp-code
|
icmp-message
} |
logging
|
precedence
precedence
|
reflective
|
source
{
sour-addr
sour-wildcard
|
any
} |
source-port operator port1
[
port2
] |
time-range
time-range-name
|
tos
tos
] *
Required
To create or modify multiple
rules, repeat this step.
The
logging
keyword takes
effect only when the module
using the ACL supports
logging.
Set the rule numbering step
step
step-value
Optional
5 by default
Configure a description for the
advanced ACL
description
text
Optional
By default, an advanced ACL
has no ACL description.
Configure a rule description
rule
rule-id comment
text
Optional
By default, an ACL rule has no
rule description.
Note that:
z
You can only modify the existing rules of an ACL that uses the match order of
config
. When
modifying a rule of such an ACL, you may choose to change just some of the settings, in which
case the other settings remain the same.
z
You cannot create a rule with, or modify a rule to have, the same permit/deny statement as an
existing rule in the ACL.
z
When the ACL match order is
auto
, a newly created rule will be inserted among the existing rules in
the depth-first match order. Note that the IDs of the rules still remain the same.
z
You can modify the match order of an ACL with the
acl number
acl-number
[
name acl-name
]
match-order
{
auto
|
config
} command, but only when the ACL does not contain any rules.
z
The rule specified in the
rule comment
command must already exist.
Configuring an Ethernet Frame Header ACL
Ethernet frame header ACLs match packets based on Layer 2 protocol header fields such as source
MAC address, destination MAC address, 802.1p priority (VLAN priority), and link layer protocol type.
They are numbered in the range 4000 to 4999.
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...