H3C S6550X-HI Series Command Reference Manual page 2146

Table of Contents

Advertisement

The
undo rule { deny | permit }
specify all the attributes of the rule for the command.
The
counting
hardware-count
hardware for all rules in an ACL. For more information about the
packet filter commands in Security Command Reference.
Examples
# Create a rule in Layer 2 ACL 4000 to permit ARP packets and deny RARP packets.
<Sysname> system-view
[Sysname] acl mac 4000
[Sysname-acl-mac-4000] rule permit type 0806 ffff
[Sysname-acl-mac-4000] rule deny type 8035 ffff
Related commands
acl
display acl
packet-filter
packet-filter global
step
time-range
rule (user-defined ACL view)
Use
to create or edit a user-defined ACL rule.
rule
Use
undo rule
Syntax
Command set 1:
rule [ rule-id ] { deny | permit } [ { { l2 | l4 }rule-string rule-mask
offset }&<1-8> ] [ counting | time-range time-range-name ] *
undo rule rule-id
undo rule { deny | permit } [ { { l2 | l4 } rule-string rule-mask offset }&<1-8> ]
[ counting | time-range time-range-name ] *
Command set 2:
rule
[ rule-id ] {
psh-value | rst rst-value | syn syn-value | urg urg-value } * | established } |
destination { dest-address dest-wildcard | any } | destination-port
{ operator port1 [ port2 ] } | { { precedence precedence | tos tos } * | dscp
dscp } { source-address source-wildcard | any } | source-port { operator
port1 [ port2 ] } | udf-format | vpn-instance vpn-instance-name ] * [ { { l2
| l4 | l5 } rule-string rule-mask offset }&<1-8> ] [ counting | time-range
time-range-name ] *
undo rule rule-id [ { { ack | fin | psh | rst | syn | urg } * | established } |
destination | destination-port | { { precedence | tos } *| dscp } urce |
source-port | udf-format
l5 | counting | time-range ] *
command can only be used to delete an entire rule. You must
keyword in this command enables match counting specific to rules, and the
keyword in the
(interface view) (Security Command Reference)
(Security Command Reference)
to delete a user-defined ACL rule.
deny
permit
|
}protocol [ { { ack ack-value | fin fin-value | psh
| vpn-instance vpn-instance-name
command enables match counting in
packet-filter
22
command , see
packet-filter
| l2 | l4 |

Advertisement

Table of Contents
loading

Table of Contents