8. Access Control List (ACL) Egress Command List
118
8.1.
create egress_access_profile
Description
This command is used to create an egress access list profile. For example, for some
hardware, it may be invalid to specify destination IPv6 address and source IPv6
address at the same time. The user will be prompted for these limitations.
Format
create egress_access_profile profile_id <value 1-4> profile_name <name 1-32>
[ethernet {vlan {<hex 0x0-0x0fff>} | source_mac <macmask 000000000000-ffffffffffff>
| destination_mac <macmask 000000000000-ffffffffffff> | 802.1p | ethernet_type} |
ip {vlan {<hex 0x0-0x0fff>} | source_ip_mask <netmask> | destination_ip_mask
<netmask> | dscp | [icmp {type | code} | igmp {type} | tcp {src_port_mask <hex 0x0-
0xffff> | dst_port_mask <hex 0x0-0xffff> | flag_mask [all | {urg | ack | psh | rst | syn |
fin}]} | udp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>} |
protocol_id_mask <hex 0x0-0xff> {user_define_mask <hex 0x0-0xffffffff>}]} | ipv6
{class | source_ipv6_mask <ipv6mask> | destination_ipv6_mask <ipv6mask> | [tcp
{src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>} | udp
{src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>} | icmp {type |
code}]}]
config egress_flow_meter [profile_id <value 1-4> | profile_name <name 1-32>] access_id <value 1-
128> [rate <value 0-1048576> {burst_size <value 0-131072>} rate_exceed [drop_packet |
remark_dscp <value 0-63>] | tr_tcm cir <value 0-1048576> {cbs <value 0-131072>} pir <value
0-1048576> {pbs <value 0-131072>} {[color_blind | color_aware]} {conform [permit |
replace_dscp <value 0-63>] {counter [enable | disable]}} exceed [permit {replace_dscp
<value 0-63>} | drop] {counter [enable | disable]} violate [permit {replace_dscp <value 0-
63>} | drop] {counter [enable | disable]} | sr_tcm cir <value 0-1048576> cbs <value 0-
131072> ebs <value 0-131072> {[color_blind | color_aware]} {conform [permit |
replace_dscp <value 0-63>] {counter [enable | disable]}} exceed [permit {replace_dscp
<value 0-63>} | drop] {counter [enable | disable]} violate [permit {replace_dscp <value 0-
63>} | drop] {counter [enable | disable]} | delete]
show egress_flow_meter {[profile_id <value 1-4> | profile_name <name 1-32>] {access_id
<value1-128>}}
create port_group id <value 1-64> name <name 16>
config port_group [id <value 1-64> | name <name 16>] [add | delete] [<portlist> | all]
delete port_group [id <value 1-64> | name <name 16>]
show port_group {id <value 1-64> | name <name 16>}
Содержание ZEQUO 6400
Страница 158: ...12 Basic IP Commands 159 Zxxx0 admin config ipif System vlan v1 Command config ipif System vlan v1 Success Zxxx0 admin ...
Страница 160: ...12 Basic IP Commands 161 ...
Страница 189: ...17 Command Logging Command List 190 ...
Страница 554: ...49 MAC based Access Control Commands 555 ...
Страница 644: ...58 Network Monitoring Commands 645 Zxxx0 admin clear attack_log Command clear attack_log Success Zxxx0 admin ...
Страница 812: ...69 QoS Commands 813 ...
Страница 839: ...73 SNMPv1 v2 v3 Commands 840 Only Administrator level users can issue this command ...
Страница 962: ...85 Virtual Router Redundancy Protocol VRRP Command List 963 ...
Страница 1050: ...91 System Log Lists 1051 ...