Assigning An Acl Globally; Assigning An Acl To A Vlan - H3C S3100 Series Operation Manual

For soliton - acl
Hide thumbs Also See for S3100 Series:
Table of Contents

Advertisement

Operation Manual (For Soliton) – ACL
H3C S3100 Series Ethernet Switches
Caution:
In terms of priority, the ACLs assigned globally, ACLs assigned to a VLAN and ACLs
assigned to a port group (or a port) rank in descending order. If a packet matches
multiple rules in these ACLs and is permitted by some rules but denied by the others,
the device permits or denies the packet based on the rule in the ACL with the highest
priority.

1.3.1 Assigning an ACL Globally

I. Configuration prerequisites
Before applying ACL rules to a VLAN, you need to define the related ACLs. For
information about defining an ACL, refer to section
section
1.2.3 Configuring Advanced
section
1.2.5 Configuring an IPv6
II. Configure procedure
Table 1-6 Assign an ACL globally
Operation
Enter system view
Assign an ACL
globally
III. Configuration example
# Apply ACL 2000 globally to filter the inbound packets on all the ports.
<Sysname> system-view
[Sysname] packet-filter inbound ip-group 2000

1.3.2 Assigning an ACL to a VLAN

I. Configuration prerequisites
Before applying ACL rules to a VLAN, you need to define the related ACLs. For
information about defining an ACL, refer to section
section
1.2.3 Configuring Advanced
section
1.2.5 Configuring an IPv6
ACL, section
ACL.
Command
system-view
packet-filter inbound
acl-rule
ACL, section
ACL.
1-13
Chapter 1 ACL Configuration
1.2.2 Configuring Basic
1.2.4 Configuring Layer 2
Description
Required
For description on the acl-rule
argument, refer to ACL Command.
1.2.2 Configuring Basic
1.2.4 Configuring Layer 2
ACL,
ACL, and
ACL,
ACL, and

Advertisement

Table of Contents
loading

Table of Contents