ZXR10 2900E Series Command Reference
4.13.38 config ingress-acl global
Purpose
This command enters the global ingress ACL instance and configures the instance.
Command Mode
Global configuration mode
Syntax
config ingress-acl global
4.13.39 ingress-acl global rule type-ip-protocol
Purpose
This command sets the rule that the global ingress ACL matches the packet with
IPv4-specified field.
Command Mode
Global ingress ACL configuration mode
Syntax
rule <1-16>{permit | deny} port {<1-28>| any}<ip-protocol>{<source-ipaddr><sip-mask>| an
y}{<destination-ipaddr><dip-mask>| any}[dscp <0-63>][fragment][cos <0-7>][<vlan-id>[<vla
n-mask>]][<source-mac><smac-mask>| any][<dest-mac><dmac-mask>| any]
Parameter Description
Parameter
<1-16>
permit
deny
<1-28>
any (first)
<ip-protocol>
SJ-20130731155059-003|2013-11-27 (R1.0)
Description
Global rule number.
If the condition matches, access is permitted.
If the condition matches, access is denied.
Binds the global rule to a port. Different devices have different
port number ranges. In the syntax, the 2928E device is used as
an example.
Binds the global rule to all ports.
This rule is only valid for messages with the specified IP protocol
field. Ignore this rule for other messages. The range of IP protocol
field value is 0 to 255.
4-248
ZTE Proprietary and Confidential