VN/UN564:1VN/UN5674
LgvUvtgco" N4" Ocpcigf" Uykvej" ENK" Iwkfg
149
destination-ip-mask
—— The destination IP address mask. It is required if you
typed the destination IP address.
time-segment
—— The time-range for the rule to take effect. By default, it is not
limited.
frag —— Enable/Disable Fragment. By default, it is disabled. If Fragment is
enabled, this rule will process all the fragments and the last piece of fragment
will be always forwarded.
Eqoocpf"Oqfg"
Global Configuration Mode
Gzcorng"
Create a Standard-IP ACL whose ID is 120, and add Rule 10 for it. In the rule,
the source IP address is 192.168.0.100, the source IP address mask is
255.255.255.0, the time-range for the rule to take effect is tSeg1, and the
packets match this rule will be forwarded by the switch:
VN/UN564:*%ceeguu/nkuv"etgcvg"
120
"
VN/UN564:*%ceeguu/nkuv" uvcpfctf"
120
twng"
10 permit
ukr
192.168.0.100
uocum
255.255.255.0
vugi
tSeg1
ceeguu/nkuv"gzvgpfgf"
Fguetkrvkqp"
The
ceeguu/nkuv"gzvgpfgf
command is used to add Extended-IP ACL rule. To
delete the corresponding rule, please use
pq"ceeguu/nkuv"gzvgpfgf
command.
U{pvcz"
ceeguu/nkuv"gzvgpfgf"
acl-id
twng
rule-id
"
{ deny
|
permit } [ [
ukr
source-ip
]
uocum
source-ip-mask
] [ [
fkr
destination-ip
]
focum
destination-ip-mask
] [
vugi
time-segment
] [
htci
{disable | enable}] [
fuer
dscp
] [
u/rqtv
s-port
] [
f/rqtv
d-port
]
[
verhnci
tcpflag
] [
rtqvqeqn
protocol
] [
keorv{rg
icmptype
] [
keoreqfg
icmpcode
]
[
vqu
tos
] [
rtk
pri
]
pq"ceeguu/nkuv"gzvgpfgf
acl-id
twng
rule-id
Rctcogvgt"
acl-id
——The desired Extended-IP ACL for configuration.
rule-id
—— The rule ID.
deny —— The operation to discard packets.
permit ——The operation to forward packets. It is the default value.