Configuring an Ethernet Frame Header ACL
Ethernet frame header ACLs filter packets based on Layer 2 protocol header fields such as source MAC
address, destination MAC address, 802.1p priority (VLAN priority), and link layer protocol type. They
are numbered in the range 4000 to 4999.
Configuration Prerequisites
If you want to reference a time range to a rule, define it with the time-range command first.
Configuration Procedure
Follow these steps to configure an Ethernet frame header ACL:
To do...
Enter system view
Create and enter Ethernet
frame header ACL view
Create or modify a rule
Set a rule numbering step
Create an ACL description
Create a rule description
Note that:
You can only modify the existing rules of an ACL that uses the match order of config. When
modifying a rule of such an ACL, you may choose to change just some of the settings, in which
case the other settings remain the same.
You cannot create a rule with, or modify a rule to have, the same permit/deny statement as an
existing rule in the ACL.
When the ACL match order is auto, a newly created rule will be inserted among the existing rules in
the depth-first match order. Note that the IDs of the rules still remain the same.
Use the command...
system-view
acl number acl-number [ name
acl-name ] [ match-order { auto |
config } ]
rule [ rule-id ] { deny | permit } [ cos
vlan-pri
|
dest-mac
dest-mask
|
lsap
lsap-wildcard
|
sour-addr
source-mask
time-range time-range-name | type
type-code type-wildcard ] *
step step-value
description text
rule rule-id comment text
2-6
––
Required
The default match order is
config.
If you specify a name for an
IPv4 ACL when creating the
ACL, you can use the acl name
acl-name command to enter
the view of the ACL later.
Required
dest-addr
To create multiple rules, repeat
lsap-code
this step.
source-mac
Note that the lsap keyword is
|
not supported if the ACL is to
be referenced by a QoS policy
for traffic classification.
Optional
The default step is 5.
Optional
By
default,
description is present.
Optional
By default, no rule description
is present.
Remarks
no
IPv4
ACL
Need help?
Do you have a question about the S7906E and is the answer not in the manual?