3Com 8800 Configuration Manual page 379

3com 8800: install guide
Hide thumbs Also See for 8800:
Table of Contents

Advertisement

3Com Switch 8800 Configuration Guide
Table 32-9 Define advanced ACL
Operation
Enter advanced ACL
view (system view)
Define an ACL rule
(advanced ACL view)
Delete an ACL rule
(advanced ACL view)
Delete an ACL or all
ACLs (system view)
Note that the port1 and port2 parameters in the command should be TCP/UDP ports for
advanced applications. For some common ports, you can use mnemonic symbols to
replace numbers. For example, you can use "bgp" to represent TCP port 179, which is
for BGP protocol.
III. Defining L2 ACLs
L2 ACLs define the Layer 2 information such as source and destination MAC
addresses, source VLAN ID, and L2 protocol type in their rules and process packets
according to these attributes.
Perform the following configurations in the specified view.
Table 32-10 Define L2 ACLs
Enter L2 ACL view (system
view)
Define an ACL rule (L2 ACL
view)
Delete an ACL rule (L2 ACL
view)
Delete an ACL or all ACLs
(system view)
acl { number acl-number | name acl-name advanced }
[ match-order { config | auto } ]
rule [ rule-id ] { permit | deny } protocol [ source
{ source-addr wildcard | any } ] [ destination { dest-addr
wildcard | any } ] [ source-port operator port1 [ port2 ] ]
[ destination-port operator port1 [ port2 ] ] [ icmp-type
type code ] [ established ] [ [ precedence precedence |
tos tos ]* | dscp dscp ] [ fragment ] [ time-range name ]
[ vpn-instance instance-name ]
undo rule rule-id [ source | destination | source-port |
destination-port | icmp-type | precedence | tos | dscp |
fragment | time-range | vpn-instance ]*
undo acl { number acl-number | name acl-name | all }
Operation
Command
Command
acl { number acl-number | name acl-name link }
[ match-order { config | auto } ]
rule [ rule-id ] { permit | deny } [ cos cos-value |
{ arp | ip | mpls [ l2lable-range ] [ exp exp-value ] |
nbx | pppoe-control | pppoe-data | rarp } | ingress
{
{
source-vlan-id
source-mac-wildcard
{ dest-mac-addr dest-mac-wildcard | any } |
time-range name ]*
undo rule rule-id
undo acl { number acl-number | name acl-name |
all }
32-9
Chapter 32 ACL Configuration
|
source-mac-addr
}*
|
any
}
|
egress

Advertisement

Table of Contents
loading

Table of Contents