
NOTE
You can configure the same name for multiple time ranges to describe a special period. Assume that the same
name
test
is configured for the following time ranges:
l
Time range 1: 2010-01-01 00:00 to 2010-12-31 23:59 (absolute time range)
l
Time range 2: 8:00 to 18:00 from Monday to Friday (periodic time range)
l
Time range 3: 14:00 to 18:00 on Saturday and Sunday (periodic time range)
The time range
test
includes 8:00-18:00 on Monday to Friday and 14:00-18:00 on Saturday and Sunday in 2010.
----End
Follow-up Procedure
Reference the time range in a Layer 2 ACL rule.
10.5.3 Creating a Layer 2 ACL
Before using a Layer 2 ACL, ensure that the Layer 2 ACL has been created. You can create a
named or numbered Layer 2 ACL.
Prerequisites
The
display acl
all
command has been executed to view all the configured ACLs. This prevents
duplicate Layer 2 ACLs from being configured.
Procedure
l
Creating a numbered Layer 2 ACL
1.
Run:
system-view
The system view is displayed.
2.
Run:
acl
[
number
]
acl-number
[
match-order
{
auto
|
config
} ]
A Layer 2 ACL with the specified number is created and the Layer 2 ACL view is
displayed.
acl-number
specifies the number of a Layer 2 ACL. The value ranges from 4000 to
4999.
match-order
specifies the matching order of Layer 2 ACL rules:
–
auto
: indicates that ACL rules are matched based on the depth first principle.
–
config
: indicates that ACL rules are matched based on the sequence in which they
were configured.
3.
(Optional) Run:
description
text
The description of the Layer 2 ACL is configured.
The description of an ACL describes the function or usage of the ACL. It is used to
differentiate ACLs.
By default, no description is configured for an ACL.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
204