ZXR10 2900E Series Configuration Guide
Command
Function
zte(cfg)#
config egress-acl hybrid number
<
700-799
>
Creates a hybrid egress ACL instance
and configures it.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}<
ip-protocol
>{<
source-ipaddr
><
sip-mask
>|
any
}{<
destination-ipaddr
><
dip-mask
>|
any
}[
dsscp
<
0-63
>][
fragment
][
coss
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]
Sets a hybrid egress ACL which
matches the protocol field of IPv4.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
ip
{<
source-ipaddr
><
sip-mask
>|
any
}{<
destination-ipaddr
><
dip-mask
>|
any
}[
dsscp
<
0-63
>][
fragment
][
coss
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]
Sets a hybrid egress ACL which
matches the IPv4 packet.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
tcp
{<
source-ipaddr
><
sip-mask
>|
any
}[
ssourrce-porrtt
<
0-65535
><
sport-mask
>]{<
destination-ipaddr
><
dip-mask
>|
any
}[
desstt-porrtt
<
0-65535
><
dport-mask
>][
dsscp
<
0-63
>][
fragment
][
coss
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]
Sets a hybrid egress ACL which
matches the IPv4-TCP packet.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
udp
{<
source-ipaddr
><
sip-mask
>|
any
}[
ssourrce-porrtt
<
0-65535
><
sport-mask
>]{<
destination-ipaddr
><
dip-mask
>|
any
}[
desstt-porrtt
<
0-65535
><
dport-mask
>][
dsscp
<
0-63
>][
fragment
][
coss
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]
Sets a hybrid egress ACL which
matches the IPv4-UDP packet.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
arp
{<
sender-ipaddr
><
sip-mask
>|
any
}{<
target-ipaddr
><
tip-mask
>|
any
}[
coss
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]
Sets a hybrid egress ACL which
matches the ARP packet.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
any
{[
ettherr-ttype
<
1501-65535
>][
coss
<
0-7
>][<
vlan-id
>[<
vlan-mask
>]][<
source-mac
><
smac-mask
>|
any
][<
dest-mac
><
dmac-mask
>|
any
]}
Sets a hybrid egress ACL which
matches the non-IPv6 packet.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
iipv6
<
ip-protocol
>{<
source-ipv6addr
><
sipv6-mask
>|
any
}{<
destination-ipv6addr
><
dipv6-mask
>|
any
}[<
vlan-id
>]
Sets a hybrid egress ACL which
matches the protocol field of IPv6.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
ipv6 tcp
{<
source-ipv6addr
><
sipv6-mask
>|
any
}[
ssourrce-porrtt
<
0-65535
><
sport-mask
>]{<
destination-ipv6addr
><
dipv6-mask
>|
any
}[
desstt-porrtt
<
0-65535
><
dport-mask
>][<
vlan-id
>]
Sets a hybrid egress ACL which
matches the IPv6-TCP packet.
zte(egress-hybrid-acl)#
rule
<
1-500
>{
permit
|
deny
}
ipv6 udp
{<
source-ipv6addr
><
sipv6-mask
>|
any
}[
ssourrce-porrtt
<
0-65535
><
sport-mask
>]{<
destination-ipv6addr
><
dipv6-mask
>|
any
}[
desstt-porrtt
<
0-65535
><
dport-mask
>][<
vlan-id
>]
Sets a hybrid egress ACL which
matches the IPv6-UDP packet.
4-48
SJ-20120409144109-002|2012-07-02(R1.0)
ZTE Proprietary and Confidential
Содержание ZXR10 2910E-PS
Страница 6: ...IV ...
Страница 8: ...II ...
Страница 264: ...Tables This page intentionally left blank ...