Chapter 8 ACL Configuration
Configuration Data
lists the configuration data of the layer-2 ACL.
Table 8-3 Configuration Data of the Layer-2 ACL
Item
Data
ACL number
200
Rule 1
Action: deny
Source MAC address: 0000.0000.0001
Protocol type: any
Rule 2
Permit any traffic
Interface
gei_1/21/1
Steps
1.
In global configuration mode, create a layer-2 ACL.
ZXAN(config)#acl link number 200
ZXAN(config-link-acl)#
Note:
The layer ACL number ranges from 200 to 299. A layer-2 ACL can be applied to the
Ethernet interface and EPON-OLT interface.
2.
Configure the ACL rules.
ZXAN(config-link-acl)#rule 1 deny any ingress 0000.0000.0001 0000.0000.0000
egress any
ZXAN(config-link-acl)#rule 2 permit any
ZXAN(config-link-acl)#exit
Note:
Each layer-2 ACL supports up to 4096 rules.
If the time range is not configured, the rule is always effective.
3.
In Ethernet interface configuration mode, apply the ACL.
ZXAN(config)#interface gei_1/21/1
ZXAN(config-if)#ip access-group 200 in
4.
(Optional) Query the ACL configuration.
ZXAN(config-if)#show acl 200
8-5
SJ-20130520164529-007|2013-06-30 (R1.0)
ZTE Proprietary and Confidential
Содержание ZXA10 C300
Страница 8: ...VI SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...
Страница 294: ...Tables This page intentionally left blank VI SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...
Страница 301: ...Glossary VoIP Voice over Internet Protocol XIII SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...