Advanced Acl - 3Com 3C13636 Configuration Manual

Router 3000 ethernet family
Hide thumbs Also See for 3C13636:
Table of Contents

Advertisement

3Com Router 3000 Ethernet Family
Configuration Guide
Then edit the ACL rule:
rule 1 deny logging
And then, the ACL rule becomes:
rule 1 deny source 1.1.1.1 0 logging
The following command can be used to delete a basic ACL rule:
undo rule rule-id [ comment text ] [ source ] [ time-range ] [ logging ] [ fragment ]
[ vpn-instance vpn-instance-name ]
Parameter description:
rule-id: Number of ACL rule, which should be an existing ACL rule number. If there
is no parameter followed, the entire ACL rule will be deleted. Otherwise, only part
of information related to the ACL rule will be deleted.
comment text: Specifies a comment for each rule.
source: Optional parameter. Only the source address information setting of ACL
rule with corresponding number will be deleted.
time-range: Optional parameter. Only the specific effective time range setting of
ACL rule with corresponding number will be deleted.
logging: Optional parameter. Only the logging qualified packet setting of ACL rule
with corresponding number will be deleted.
fragment: Optional parameter. Only the validation setting solely for
non-first-fragment of ACL rule with corresponding number will be deleted.
vpn-instance: Optional parameter. If it has been specified, the deletion operation
will delete only the settings involved the vpn-instance in the ACL rule with the
specified number.

5.1.6 Advanced ACL

Advanced ACL can define rules by using such contents of data packet as source
address information, destination address information, IP carried protocol type and
protocol oriented feature (for example, source port and destination port of TCP, type
and code of ICMP). Advance ACL can be used to define more accurate, diversified and
flexible rules than basic ACL.
An advanced ACL can be created and advanced ACL view be entered by the previously
mentioned ACL command. In advance ACL view, the rules of advanced ACL can be
created.
The following command can be used to define an advanced ACL rule:
rule [ rule-id ] { permit | deny | comment text } protocol source [ sour-addr
sour-wildcard | any ] destination [ dest-addr dest-mask | any ] [ soucre-port operator
port1 [ port2 ] ] [ destination-port operator port1 [ port2 ] ] [ icmp-type { icmp-message
|icmp-type icmp-code} ] [ dscp dscp ] [ precedence precedence ] [ tos tos ]
[ time-range time-name ] [ logging ] [ fragment ] [ vpn-instance ]
3Com Corporation
5-4
Chapter 5 ACL Configuration

Advertisement

Table of Contents
loading

This manual is also suitable for:

3c13636-us - router 30363000 series

Table of Contents