Configuration Guide
Access
Control List Configuration
Note
ACL80 support matching against Ethernet packets, 803.3 SNAP packets,
and 802.311c packets. If the value for matching DSAP to the cnt1 field is set
to AAAA03, it indicates to match the 803.3 SNAP packets. If the value is set
to E0E003, it indicates to match the 803.311c packets. This field cannot be
set to match Ethernet packets.
Configuration note:
The ACL180 has only 16 bytes for matching. If the 16 bytes are used, no
fields other than the 16 bytes can be matched. For example:
Ruijie(config)#
expert access-list advanced
name
Ruijie(config-exp-dacl)#
permit
11223344556677889900aabbccd
deeff ffffffffffffffffffffffffffffffff 50
If you use the following command to add another ACE:
Ruijie(config-exp-dacl)#permit 11223344556677889900aabbccd
deeff ffffffffffffffffffffffffffffffff 54
The configuration will fail because the 16 bytes are used by the first ACE. To
match the second ACE, you must firstly delete the first ACE.
Configuring TCP Flag Filtering Control
The TCP Flag filtering feature provides a flexible mechanism. At present, TCP Flag filtering control
supports the match-all option. Namely, when the TCP Flags in a received message exactly match
those defined in the ACL table entry, the message will be checked by the ACL rule. A user can define
any combination of TCP Flags to filter some messages with specific TCP Flags.
For example,
permit tcp any any match-all rst
Allow the messages with a TCP Flag RST set and 0 in other positions to pass
Note
When the protocol number of the naming ACL and numerical value
configuration is TCP, you can select to configure this filtering feature. MAC
extended and IP standard ones do not have this function.
Please configure a TCP Flag by following these steps:
Command
Function
Ruijie(config)#
ip access-list
extended
{ id |
name
}
Enter the access list configuration mode
Ruijie(config-ext-nacl)# [
sn
] [
permit
|
deny
]
tcp
source
source-wildcard
[
operator port
[port]
]
destination
destination-wildcard
[
operator port
[ port ]
] [
match-all
flag-name
][
precedence
precedence
]
Add table entries for ACL. For details about
commands, please see command reference.
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...