2-5
z
You can modify the match order of an ACL with the
acl number
acl-number
[
name acl-name
]
match-order
{
auto
|
config
} command, but only when the ACL does not contain any rules.
z
The rule specified in the
rule comment
command must already exist.
Configuring an Ethernet Frame Header ACL
Ethernet frame header ACLs match packets based on Layer 2 protocol header fields such as source
MAC address, destination MAC address, 802.1p priority (VLAN priority), and link layer protocol type.
They are numbered in the range 4000 to 4999.
Configuration Prerequisites
If you want to reference a time range in a rule, define it with the
time-range
command first.
Configuration Procedure
Follow these steps to configure an Ethernet frame header ACL:
To do…
Use the command…
Remarks
Enter system view
system-view ––
Create an Ethernet frame
header ACL and enter its view
acl number
acl-number
[
name
acl-name
] [
match-order
{
auto
|
config
} ]
Required
The default match order is
config
.
If you specify a name for an
IPv4 ACL when creating the
ACL, you can use the
acl
name
acl-name
command to enter
the view of the ACL later.
Create or modify a rule
rule
[
rule-id
] {
deny
|
permit
}
[
cos vlan-pri | dest-mac
dest-addr
dest-mask | lsap
lsap-type
lsap-type-mask |
source-mac
sour-addr
source-mask
|
time-range
time-range-name | type
protocol-type
protocol-type-mask
] *
Required
To create or modify multiple
rules, repeat this step.
Note that the
lsap
keyword is
not supported if the ACL is to
be referenced by a QoS policy
for traffic classification.
Set the rule numbering step
step
step-value
Optional
5 by default
Configure a description for the
Ethernet frame header ACL
description
text
Optional
By default, an Ethernet frame
header ACL has no ACL
description.
Содержание S5810 Series
Страница 307: ...ii Configured Multicast Group Policy Fails to Take Effect 1 32...
Страница 648: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...
Страница 812: ...1 7 Role Slave Sysname stack_3 DeviceD Device type S5810 50S MAC address 000f e200 1003...