![Huawei Quidway S5600 Скачать руководство пользователя страница 703](http://html.mh-extra.com/html/huawei/quidway-s5600/quidway-s5600_operation-manual_169841703.webp)
Operation Manual – ACL
Quidway S5600 Series Ethernet Switches-Release 1510
Chapter 1 ACL Configuration
Huawei Technologies Proprietary
1-15
1.6 Defining User-Defined ACLs
Using a byte, which is specified through its offset from the packet header, in the packet
as the starting point, user-defined ACLs perform logical AND operations on packets
and compare the extracted string with the user-defined string to find the matching
packets for processing.
User-defined ACL numbers range from 5000 to 5999.
1.6.1 Configuration Preparation
To configure a time range-based ACL rule, you need first to define the corresponding
time range, as described in section 1.2 “Configuring Time Ranges”.
1.6.2 Configuration Procedure
Table 1-13
Define a user-defined ACL rule
Operation
Command
Description
Enter system view
system-view
—
Create or enter
user-defined ACL
view
acl number
acl-number
Required
Define an ACL rule
rule
[
rule-id
] {
permit
|
deny
} [
rule-string
rule-mask
offset
] &<1-8> [
time-range
name
]
Required
Define the
description for the
ACL rule
description
text
Optional
Define a comment
string for the ACL
rule
rule
rule-id
comment
text
Optional
Display ACL
information
display
acl
{
all
|
acl-number
}
Optional
This
command can be
executed in any view.
Note:
For the user-defined ACL rules, if you set to match the fields after the VLAN tag, two
VLAN tags are added for matching of either tagged or untagged packets. For the
packets with their type filed as 0800, the offset value should be 20.
When you specify the rule ID by using the
rule
command, note that: