14-13
Table 14-4
Match criteria and other rule information for advanced IPv4 ACL rules
Parameters
Function
Description
source
{
sour-addr
sour-wildcard
|
any
}
Specifies a source
address.
The
sour-addr sour-wildcard
argument
combination specifies a source IP address
in dotted decimal notation. A wildcard of
zero indicates a host address. The
any
keyword indicates any source IP address.
destination
{
dest-addr
dest-wildcard
|
any
}
Specifies a destination
address.
The
dest-addr dest-wildcard
argument
combination specifies a destination IP
address in dotted decimal notation. A
wildcard of zero indicates a host address.
The
any
keyword indicates any destination
IP address.
precedence
precedence
Specifies an IP
precedence value.
The
precedence
argument can be a
number in the range 0 to 7, or in words,
routine
(0),
priority
(1),
immediate
(2),
flash
(3),
flash-override
(4),
critical
(5),
internet
(6), or
network
(7).
tos
tos
Specifies a ToS
preference.
The
tos
argument can be a number in the
range 0 to 15, or in words,
max-reliability
(2),
max-throughput
(4),
min-delay
(8),
min-monetary-cost
(1), or
normal
(0).
dscp
dscp
Specifies a DSCP priority.
The
dscp
argument can be a number in the
range 0 to 63, or in words,
af11
(10),
af12
(12),
af13
(14),
af21
(18),
af22
(20),
af23
(22),
af31
(26),
af32
(28),
af33
(30),
af41
(34),
af42
(36),
af43
(38),
cs1
(8),
cs2
(16),
cs3
(24),
cs4
(32),
cs5
(40),
cs6
(48),
cs7
(56),
default
(0), or
ef
(46).
logging
Specifies to log matched
packets.
This function requires that the module
using the ACL support logging.
reflective
Specifies that the rule be
reflective.
A rule with the
reflective
keyword can be
defined only for TCP, UDP, or ICMP
packets and can only be a permit
statement.
vpn-instance
vpn-instance-name
Specifies a VPN instance.
The
vpn-instance-name
argument is a
case-sensitive string of 1 to 31 characters.
Without this combination, the rule applies
to only non-VPN packets.
fragment
Indicates that the rule
applies to only non-first
fragments.
Without this keyword, the rule applies to all
fragments and non-fragments.
time-range
time-range-name
Specifies the time range
in which the rule takes
effect.
The
time-range-name
argument is a case
insensitive string of 1 to 32 characters. It
must start with an English letter and
cannot be the English word of all to avoid
confusion.
Setting the
protocol
argument to
tcp
or
udp
, you may define the parameters shown in
.
Содержание E4510-48G
Страница 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Страница 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Страница 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Страница 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Страница 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Страница 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Страница 857: ...iii 7 Track Configuration Commands 7 1 Track Configuration Commands 7 1 display track 7 1 track nqa 7 2 ...
Страница 914: ...5 17 Sysname reset oam ...
Страница 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Страница 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...