Operation Manual – ACL
H3C S5500-SI Series Ethernet Switches
<Sysname> system-view
[Sysname] acl number 4000
[Sysname-acl-ethernetframe-4000] rule deny cos 3
# Verify the configuration.
[Sysname-acl-ethernetframe-4000] display acl 4000
Ethernet frame ACL
ACL's step is 5
rule 0 deny cos excellent-effort(0 times matched)
2.5 Displaying and Maintaining IPv4 ACLs
Display
about a specified or all
IPv4 ACLs
Display the configuration
and state of a specified
or all time ranges
Clear the statistics about
the specified or all ACLs
2.6 IPv4 ACL Configuration Example
2.6.1 Network Requirements
Different departments of an enterprise are interconnected on the intranet through the
ports of a switch. The IP address of the wage query server is 192.168.1.2. Devices of
the R&D department are connected to the GigabitEthernet1/0/1 port of the switch.
Apply an ACL to deny requests sourced from the R&D department and destined for the
wage server during the working hours (8:00 to 18:00).
2.6.2 Network Diagram
R&D Department
R&D Department
Figure 2-1 Network diagram for ACL configuratio
4000, 1 rule,
To do...
information
display acl { all | acl-number }
display time-range
time-name }
reset
acl-number }
To a router
To a router
#3
#3
#2
#2
#1
#1
Switch
Switch
Use the command...
{
acl
counter
{
Salary server
Salary server
192.168.1.2
192.168.1.2
n
2-8
Chapter 2 IPv4 ACL Configuration
Remarks
Available
view
all
|
all
|
Available in user
view
in
any