Huawei Quidway S3500 Series Operation Manual page 333

Hide thumbs Also See for Quidway S3500 Series:
Table of Contents

Advertisement

Operation Manual - QoS/ACL
Quidway S3500 Series Ethernet Switches
Note:
For S3526 series and S3026 F switches, there are some limits:
protocol type (the parameter protocol in rule command) can't be configured if the
user configures the IP-any, any-IP, NET-any, any-NET rules( source IP address is
host IP address or NET segment address and destination address is any in the
rules, or source IP address is any and destination address is host IP address or
NET segment address in the rules). Otherwise the system will prompt the
configuration is not available.
doesn't support ToS, IP precedence, DSCP priority parameter when define
advanced ACL.
parameter icmp-type is only supported when user defines advance ACL. ICMP
packet type and code (the parameter type code in rule command) can't be
configured. Otherwise the system will prompt the configuration is not available.
You can use the following command to define advanced ACL.
Perform the following configuration in corresponding view.
Table 1-6 Defining the advanced ACL
Operation
Enter
view(from system view)
Add a sub-item to the
ACL(from
ACL view)
Delete a sub-item from
the ACL(from advanced
ACL view)
Delete one ACL or all the
ACL(from system view)
The advanced ACL is identified with the numbers ranging from 3000 to 3999.
Note that, the port1 and port2 in the above command specify the TCP or UDP ports
used by various high-layer applications. For some common port numbers, you can use
the mnemonic symbols as shortcut. For example, "bgp" can represent the TCP number
179 used by BGP.
advanced
ACL
acl { number acl-number | name acl-name advanced }
[ match-order { config | auto } ]
rule [ rule-id ] { permit | deny } protocol [ source
source-addr wildcard | any ] [ destination dest-addr
wildcard | any ] [ source-port operator port1 [ port2 ] ]
advanced
[ destination-port operator port1 [ port2 ] ] [ icmp-type
type code ] [ established ] [ [ precedence precedence |
tos tos ]* | dscp dscp ] [ fragment ] [ time-range name ]
undo rule rule-id [ source ] [ destination ]
[ source-port ] [ destination-port ] [ icmp-type ]
[ precedence ] [ tos ] [ dscp ] [ fragment ]
[ time-range ]
undo acl { number acl-number | name acl-name | all }
Huawei Technologies Proprietary
Command
1-7
Chapter 1 ACL Configuration

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents