2-2
z
Compound time range created using the
time-range
time-range-name
start-time
to
end-time
days
{
from time1 date1
[
to time2 date2
] |
to time2 date2
} command. A time range thus created recurs
on the day or days of the week only within the specified period. For example, to create a time range
that is active from 12:00 to 14:00 on Wednesdays between January 1, 2004 00:00 and December
31, 2004 23:59, you may use the
time-range test 12:00 to 14:00 wednesday from 00:00
01/01/2004 to 23:59 12/31/2004
command.
You may create individual time ranges identified with the same name. They are regarded as one time
range whose active period is the result of ORing periodic ones, ORing absolute ones, and ANDing
periodic and absolute ones.
If you do not specify the start time and date, the time range starts from the earliest time that the system
supports, namely 00:00 01/01/1970. If you do not specify the end time and date, the time range ends at
the latest time that the system supports, namely 24:00 12/31/2100.
Configuring a Basic IPv4 ACL
Basic IPv4 ACLs match packets based on only source IP address. They are numbered from 2000 to
2999.
Configuration Prerequisites
If you want to reference a time range in a rule, define it with the
time-range
command first.
Configuration Procedure
Follow these steps to configure a basic IPv4 ACL:
To do…
Use the command…
Remarks
Enter system view
system-view
––
Create a basic IPv4 ACL and
enter its view
acl number
acl-number
[
name
acl-name
] [
match-order
{
auto
|
config
} ]
Required
The default match order is
config
.
If you specify a name for an
IPv4 ACL when creating the
ACL, you can use the
acl
name
acl-name
command to enter
the view of the ACL later.
Create or modify a rule
rule
[
rule-id
] {
deny
|
permit
}
[
fragment
|
logging
|
source
{
sour-addr sour-wildcard
|
any
} |
time-range
time-range-name
] *
Required
To create or modify multiple
rules, repeat this step.
Note that the
logging
keyword
is not supported if the ACL is to
be referenced by a QoS policy
for traffic classification.
Set the rule numbering step
step
step-value
Optional
5 by default
Содержание S5810 Series
Страница 307: ...ii Configured Multicast Group Policy Fails to Take Effect 1 32...
Страница 648: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...
Страница 812: ...1 7 Role Slave Sysname stack_3 DeviceD Device type S5810 50S MAC address 000f e200 1003...