Zte ZXR10 2900E series Configuration Manual page 97

Easy-maintenance secure switch
Hide thumbs Also See for ZXR10 2900E series:
Table of Contents

Advertisement

Command
zte(global-acl-group)#
{<1-28>| any} udp {<source-ipaddr><sip-mask>| any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>| any}[d
est-port <0-65535><dport-mask>][dscp <0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>| any]
zte(global-acl-group)#
port {<1-28>| any} arp {<sender-ipaddr><sip-mask>|
any}{<target-ipaddr><tip-mask>| any}[cos <0-7>][<vlan-id>[<vlan-
mask>]][<source-mac><smac-mask>| any][<dest-mac><dmac-mask>|
any]
zte(global-acl-group)#
port {<1-28>| any} any {[ether-type <1501-65535>][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>| any]}
zte(cfg)#
zte(egress-basic-acl)#
source-ipaddr>< sip-mask>| any}[ fragment]
zte(cfg)#
zte(cfg)#
zte(egress-extend-acl)#
deny}< ip-protocol>{< source-ipaddr>< sip-mask>| any}{<
destination-ipaddr>< dip-mask>| any}[ dsscp < 0-63>][ fragment]
zte(egress-extend-acl)#
source-ipaddr>< sip-mask>| any}{< destination-ipaddr>< dip-mask>|
any}[ iicmp-ttype < 0-254>< icmp-code>][ dsscp < 0-63>][
fragment]
zte(egress-extend-acl)#
source-ipaddr>< sip-mask>| any}{< destination-ipaddr>< dip-mask>|
any}[ dsscp < 0-63>][ fragment]
zte(egress-extend-acl)#
source-ipaddr>< sip-mask>| any}[ ssourrce-porrtt < 0-65535><
sport-mask>]{< destination-ipaddr>< dip-mask>| any}[ desstt-porrtt
< 0-65535>< dport-mask>][ establishing | established][ dsscp <
0-63>][ fragment]
SJ-20130731155059-002|2013-11-27 (R1.0)
rule <1-500>{permit | deny} port
rule <1-500>{permit | deny}
rule <1-500>{permit | deny}
config egress-acl basic number < 400-499>
rule < 1-500>{ permit | deny}{<
clear egress-acl basic number < 400-499>
config egress-acl extend number < 500-599>
rule < 1-500>{ permit |
rule < 1-500>{ permit | deny} icmp {<
rule < 1-500>{ permit | deny} ip {<
rule < 1-500>{ permit | deny} tcp {<
Chapter 5 Service Configuration
5-49
ZTE Proprietary and Confidential
Function
Sets the rule that a global ingress
ACL matches IPv4–UDP packets.
Sets the rule that a global ingress
ACL is used to match ARP
packets.
Sets the rule that a global ingress
ACL is used to match non IPv6
packets.
Creates a basic egress ACL
instance and configures it.
Sets a basic egress ACL.
Clears a basic egress ACL
instance.
Creates an extended egress ACL
instance and configures it.
Sets an extended egress ACL that
matches specified fields of IPv4
packets.
Sets an extended egress ACL that
matches ICMP packets.
Sets an extended egress ACL that
matches IP packets.
Sets an extended egress ACL that
matches TCP packets.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents