3Com E4500-24 Cli Configuration Manual page 500

Hp e4500-24: user guide
Table of Contents

Advertisement

To do...
Enter system view
Create a user-defined
ACL and enter
user-defined ACL view
Define an ACL rule
Define a comment for the
ACL rule
Define a description for
the ACL
When configuring a rule that matches specific fields of packets, take the following two items into
account:
If VLAN-VPN is not enabled, each packet in the switch carries one VLAN tag, which is 4 bytes long.
If VLAN-VPN is enabled on a port, each packet in the switch carries two VLAN tags, which is 8
bytes long.
Note that:
You can modify any existent rule of a user-defined ACL. If you modify only the time range and/or
action, the unmodified parts of the rule remain the same. If you modify the rule-string rule-mask
offset combinations, however, the new combinations will replace all of the original ones.
If you do not specify the rule-id argument when creating an ACL rule, the rule will be numbered
automatically. If the ACL has no rules, the rule is numbered 0; otherwise, the number of the rule will
be the greatest rule number plus one. If the current greatest rule number is 65534, however, the
system will display an error message and you need to specify a number for the rule.
The content of a modified or created rule cannot be identical with the content of any existing rules;
otherwise the rule modification or creation will fail, and the system prompts that the rule already
exists.
Configuration example
# Configure ACL 5000 to deny all TCP packets, provided that VLAN-VPN is not enabled on any port. In
the ACL rule, 06 is the TCP protocol number, ff is the mask of the rule, and 27 is the protocol field offset
of an internally processed IP packet.
<Sysname> system-view
[Sysname] acl number 5000
[Sysname-acl-user-5000] rule deny 06 ff 27
# Display the configuration information of ACL 5000.
[Sysname-acl-user-5000] display acl 5000
User defined ACL
5000, 1 rule
Use the command...
system-view
acl number acl-number
rule [ rule-id ] { permit | deny }
[ rule-string rule-mask offset ] &<1-8>
[ time-range time-name ]
rule rule-id comment text
description text
1-9
Remarks
Required
Required
For information about
rule-string, refer to ACL
Commands.
Optional
No description by default
Optional
No description by default

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500

Table of Contents