Chapter 4 Service Configuration
Command Mode
Layer 2 egress ACL configuration mode
Syntax
rule
<
1-500
>{
permit
|
deny
}
ip
{[
cos
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
dest-mac
><
dmac-mask
>|
any
]}
Parameter Description
Parameter
Description
<
1-500
>
Rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
ip
This rule is only valid for IP packet. Non-IP packet ignores this
rule.
cos
<
0-7
>
This rule is only valid for the cos-specified message. Other
messages ignore this rule. The range of cos is 0 to 7.
<
vlan-id
>
This rule is only valid for messages with the specified VLAN ID.
Ignore this rule for other messages. The rule of VLAN ID is 1
to 4094.
<
vlan-mask
>
Optional VLAN mask. The default value is 0xfff.
<
dest-mac
>
Destination MAC address of the transmitted packet.
<
dmac-mask
>
Destination MAC mask.
any
The any keyword is used as the abbreviation of destination MAC
address 00.00.00.00.00.00 and mask 00.00.00.00.00.00
Guidelines
The IP rule can match cos fields, VLAN fields, source-specified MACs, and any destination
MACs.
4.13.58 egress-acl link rule type-arp
Purpose
This command sets the rule that the layer–2 egress ACL matches ARP packet.
Command Mode
Layer 2 egress ACL configuration mode
4-269
SJ-20130731155059-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential