
Classification
Rule
Type
Function
Description
Naming mode
Numbered
ACL
A numbered ACL is
identified by a number,
which can be specified to
reference the ACL.
-
Named
ACL
A named ACL is identified
by a character string name,
which can be specified to
reference the ACL. Named
ACLs are easy to identify
and remember.
The AR1200-S supports
flexible ACL naming modes.
You can also specify a number
for a named ACL. If no ACL
number is specified for a
named ACL, the system
allocates an ACL number to
the named ACL.
shows information that can be used by basic ACLs, advanced ACLs, and Layer 2
ACLs to define rules. Advanced ACLs can define rules based on IP version information and the
type of the protocol over IP, such as Generic Routing Encapsulation (GRE), Internet Group
Management Protocol (IGMP), IPinIP, Open Shortest Path First (OSPF), Transmission Control
Protocol (TCP), User Datagram Protocol (UDP), and Internet Control Management Protocol
(ICMP).
Table 10-2
Information that can be used by different types of ACLs to define rules
Information Defined in
an ACL
Basic
ACL
Advanced ACL
Layer 2
ACL
-
IP
GRE,
IGMP,
IPinIP,
and
OSPF
TCP
UDP
ICMP -
Layer 3
information
Source IP
address
Yes
Yes
Yes
Yes
Yes
Yes
No
Destination
IP address
No
Yes
Yes
Yes
Yes
Yes
No
DiffServ
Codepoint
(DSCP)
No
Yes
Yes
Yes
Yes
Yes
No
Priority
No
Yes
Yes
Yes
Yes
Yes
No
Fragment
flag
Yes
Yes
Yes
Yes
Yes
Yes
No
Type of
Service
(ToS)
No
Yes
Yes
Yes
Yes
Yes
No
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
186