Huawei Quidway S3500 Series Operation Manual page 335

Hide thumbs Also See for Quidway S3500 Series:
Table of Contents

Advertisement

Operation Manual - QoS/ACL
Quidway S3500 Series Ethernet Switches
S3526 has some restrictions on ACL configuration in implementing QOS function using
traffic classification. The restriction details are listed in the following table.
Table 1-9 ACL configuration restriction for QoS function on S3526
QoS
function
Packet
filter
Note:
The Layer-3 ACL includes the advanced ACL.
In the description of the rules: MAC----MAC address, PORT----the switch port,
IP----the host IP address, ANY----any MAC address in Layer-2 ACL and any IP
address in Layer-3 ACL, NET----the segment IP address. The MAC, IP, ANY, NET
and PORT before the character "-" represent the source addresses or receive port;
the ones behind are the destination addresses or transmit port.
MAC-MAC stands for a Layer-2 ACL rule from source MAC address to destination
MAC address, such as "rule 0 permit ingress 00e0-fc01-0101 1 egress
00e0-fc01-0102 1 time-range huawei ".
PORT-PORT stands for a Layer-2 ACL rule from received ethernet port to sent
ethernet port, such as "rule 0 permit ingress interface ethernet0/1 egress interface
ethernet 0/2 time-range huawei ".
MAC-PORT stands for a Layer-2 ACL rule from source MAC address to sent
ethernet port, such as "rule 0 permit ingress 00e0-fc01-0101 1 egress interface
ethernet 0/1 time-range huawei ".
IP-IP stands for lay-3 ACL rules from source host IP address to destination host IP
address (the wildcard parameter can only be 0) , such as "rule 0 permit ip source
1.1.1.1 0 destination 2.2.2.2 0 time-range huawei".
NET-NET stands for lay-3 ACL rules from source segment IP address to destination
segment IP address (the wildcard parameter can not be 0), such as "rule 0 permit ip
source 1.1.1.1 0.0.255.255 destination 2.2.2.2 0.0.255.255 time-range huawei".
MAC-any stands for lay-2 ACL rule from source MAC address to any destination
MAC address, such as "rule 0 permit ingress 00e0-fc01-0101 1 egress any
time-range huawei", and so do any-MAC, IP-any, any-IP, NET-any and any-NET
rules.
Implementation
Packet filter only supports using the ACL of deny
packet-filter
operation.
{
ip-group
The Layer-2 ACL supports using the rules of
{
acl-number
|
MAC-MAC,
acl-name } [ rule
MAC-ANY,
rule ] | link-group
ANY-PORT.
{
acl-number
|
The Layer-3 ACL supports using the rules of
acl-name } [ rule
IP-IP, IP-NET, NET-NET, IP-ANY, ANY-IP,
rule ] }
NET-ANY and ANY-NET.
Huawei Technologies Proprietary
1-9
Chapter 1 ACL Configuration
Restrictions on ACL configuration
MAC-PORT,
ANY-MAC,
PORT-PORT,
PORT-ANY
and

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents