1.5.3 Filtering the Traffic That Matches an ACL Rule
Context
By filtering the traffic that matches an ACL rule, the S3700 rejects or permits the packets that
match the ACL rule so that the traffic is controlled.
Procedure
l
Configuring traffic filtering globally
1.
Run:
system-view
The system view is displayed.
2.
Run:
traffic-filter
[
vlan
vlan-id
]
inbound
acl
{ [
ipv6
] {
bas-acl
|
adv-
acl
|
name
acl-name
} |
l2-acl
|
user-acl
} [
rule
rule-id
]
The incoming packets matching an ACL rule are filtered on an interface.
NOTE
If the value of
vlan
vlan-id
is specified, it indicates that VLAN-based traffic filtering is
configured and the traffic matching an ACL rule is filtered on all interfaces on the VLAN.
If the value of
vlan
vlan-id
is not specified, the statistics on the traffic matching an ACL rule
are collected on all interfaces of the device.
A Layer 2 ACL and a Layer 3 ACL can be set in the
traffic-filter
command simultaneously.
The Layer 3 ACL and its rules can be configured only after the Layer 2 ACL and its rules are
configured. The Layer 2 ACL number ranges from 4000 to 4999 and the Layer 3 ACL number
ranges from 2000 to 2999 or 3000 to 3999.
To configure both Layer 2 ACLs and Layer 3 ACLs on a switch interface, use the following
command:
traffic-filter
[
vlan
vlan-id
]
inbound
acl
{
l2-acl
|
name
acl-name
} [
rule
rule-id
]
acl
{
bas-
acl
|
adv-acl
|
name
acl-name
} [
rule
rule-id
]
l
Configuring traffic filtering on an interface
1.
Run:
system-view
The system view is displayed.
2.
Run:
interface
interface-type
interface-number
The interface view is displayed.
Or, run:
interface eth-trunk
trunk-id
The Eth-Trunk interface view is displayed.
3.
Run:
traffic-filter
inbound
acl
{ [
ipv6
] {
bas-acl
|
adv-acl
|
name
acl-name
}
|
l2-acl
|
user-acl
} [
rule
rule-id
]
The incoming packets matching an ACL rule are filtered on an interface.
S3700HI Ethernet Switches
Configuration Guide - QoS
1 Class-based QoS Configuration
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
31