![H3C S5120-SI Series Скачать руководство пользователя страница 503](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174503.webp)
2-5
Configuration Prerequisites
If you want to reference a time range in a rule, define it with the
time-range
command first.
Configuration Procedure
Follow these steps to configure an Ethernet frame header ACL:
To do…
Use the command…
Remarks
Enter system view
system-view ––
Create an Ethernet frame
header ACL and enter its view
acl number
acl-number
[
name
acl-name
] [
match-order
{
auto
|
config
} ]
Required
The default match order is
config
.
If you specify a name for an
ACL when creating the ACL,
you can use the
acl
name
acl-name
command to enter
the view of the ACL later.
Create or modify a rule
rule
[
rule-id
] {
deny
|
permit
}
[
cos vlan-pri
|
dest-mac
dest-addr
dest-mask
| {
lsap
lsap-type
lsap-type-mask
|
type
protocol-type
protocol-type-mask
} |
source-mac
sour-addr
source-mask
|
time-range
time-range-name
] *
Required
To create or modify multiple
rules, repeat this step.
Set the rule numbering step
step
step-value
Optional
5 by default
Configure a description for the
Ethernet frame header ACL
description
text
Optional
By default, an Ethernet frame
header ACL has no ACL
description.
Configure a rule description
rule
rule-id comment
text
Optional
By default, an Ethernet frame
header ACL rule has no rule
description.
Note that:
z
You can only modify the existing rules of an ACL that uses the match order of
config
. When
modifying a rule of such an ACL, you may choose to change just some of the settings, in which
case the other settings remain the same.
z
You cannot create a rule with, or modify a rule to have, the same permit/deny statement as an
existing rule in the ACL.
z
When the ACL match order is
auto
, a newly created rule will be inserted among the existing rules in
the depth-first match order. Note that the IDs of the rules still remain the same.
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...