2514
C
168: ACFP C
HAPTER
Example
C
ONFIGURATION
OMMANDS
Note the following:
When you use this command to display ACFP rule information in order of
■
policy, if you specify neither client ID nor policy index, the rule information of all
the policies will be displayed.
When you use this command to display ACFP rule information in order of
■
outbound/inbound interface, if you specify no interface, the rule information
for all the inbound interfaces or outbound interfaces will be displayed.
# Display ACFP rule information in order of inbound interface.
<Sysname> display acfp rule-info in-interface ethernet 1/0
In-Interface:
ACFP rule total number: 1
ClientID:2
SIP:192.168.132.123
DIP:192.168.112.114
Protocol:ipinip
Action:redirect
# Display ACFP rule information in order of policy.
<Sysname> display acfp rule-info policy 1 1
ACFP Rule total number: 1
ClientID:1
SIP:192.168.132.122
DIP:192.168.112.115
Protocol:ipinip
Action:redirect
Table 653 Description on the fields of the display acfp rule-info command
Field
In-Interface
Out-Interface
ACFP rule total number
ClientID
Policy-Index
Rule-Index
ContextID
SIP
SMask
SPort
DIP
DMask
DPort
Protocol
Establish
Fragment
e1/0
Policy-Index:2
SMask:0.0.0.255
DMask:0.0.0.255
Establish:false
Fragment:false
Status:active
Policy-Index:1
SMask:0.0.0.255
DMask:0.0.0.255
Establish:false
Fragment:false
Status:inactive
Description
Inbound interface of the packet
Outbound interface of the packet
Total number of ACFP rules
Client ID, index of client list
Policy index
Rule index
Context ID
Source IP address
Inverse mask of source IP address
Source port number
Destination IP address
Inverse mask of destination IP address
Destination port number
Protocol of the packet: GRE, ICMP, IGMP, IPinIP, OSPF, TCP,
UDP, IP, and so on.
Whether the packet is a TCP connection establishing packet:
true (TCP connection establishing packet) and false (indicates
all the packets, not concerned about whether the packet is a
TCP connection establishing packet)
Whether the packet is a fragment: true (fragment) and false
(indicates all the packets, not concerned about whether the
packet is a fragment)
Rule-Index:5
SPort:65500 to 65535
DPort:65500 to 65535
Tos:1
Pre:1
Rule-Index:1
SPort:65500 to 65535
DPort:65500 to 65535
DSCP:AF11