User Manual
7. ACL service configuration
79
www.qtech.ru
Ipv6 hybrid
OLT (config) # ACL ipv6 hybrid 9999
OLT (config-ACL-ipv6-hyb-rule) # rule 1 permit protocol ip source
any ignore destination any ignore flow-label any traffic-class any
type ip vlan any cos any src-mac any ignore dst-mac any ignore
Parameter description:
Permit:
keywords
that
allow
qualified
packets
to
pass
through.
Use
this
parameter
when
you need to configure ACL rules that allow qualified packets to
pass.
Deny: Keywords that discard the eligible packets. Use this parameter when you need to
configure the ACL rule to reject the packets.
Source: Specify the source IP of the packets in the ACL rules. It is optional parameter,
which can match any source IP address if it is not configured.
Packet source IP address
Sour-addr:
The
source
IP
address
of
packets
in
ACL
rule.
Can
be
unspecified,
if
not
specified,
any source address can match. Dotted decimal
representation.
Sour-wildcard:
the
source
IP
address
wildcard
charater,
dotted
decimal
format,
is
the
source IP address wildcard mask. Use this parameter when matching a
subnet.
User’s guide:
When the specified access control list number to be visited does not exist, create a new
access control list, and enter the corresponding ACL configuration mode.
When the serial number already exists, go directly to the corresponding ACL configuration
mode.
The matching rules that the system supports include basic ACL(standard), senior ACL
(extend), link-layer ACL (link) and self-defined type ACL (hybrid), for ACL-matched packets
and
message,
can
support
the
filter,
flow
mirroring,
traffic
restrictions,
priority
tag,
redirection and traffic
statistics.
When
removing
the
access
control
list,
the
access
control
list
that
has
been
sent
to
the
port can't be deleted, if you need to delete, please use the "ACL action" command which
correspond to no to cancel the visiting of the access control
list.
The "all" in "No ACL rule all" is only used as index, can only be issued when configuring
"ACL rule all".
When using "ACL user", need to add extra 4 bytes after the MAC address (offset=16).
When a message flow match with more than two rules , and these rules are user
defined/non user defined at the same time, the matching order is as follows:
Same level (standard\extend\link\hybrid\ipv6, standard\ipv6, extend\ipv6,
hybrid\user):
Simultaneous activation (all), larger rule-id has higher priority;
When not activated at the same time, larger rule-id has higher priority;
Different levels:
Larger ACL ID has a higher priority.
Содержание OLT-QSW-9010
Страница 1: ...USER MANUAL www qtech ru QSW 9010 CLI Configuration user manual QSW 9010 ...
Страница 23: ...User Manual 2 Basic service configuration 23 www qtech ru ...
Страница 71: ...User Manual 6 QoS service configuration 71 www qtech ru ...
Страница 96: ...User Manual 12 Port statistics and PM statistics 96 www qtech ru ...