Operation Manual – ACL
H3C S5600 Series Ethernet Switches
1.1.3 Types of ACLs Supported by S5600 Series Ethernet Switches
The following types of ACLs are supported by S5600 series Ethernet switches:
Basic ACL
Advanced ACL
Layer 2 ACL
User-defined ACL
In addition, ACLs defined on S5600 series Ethernet switches can be applied to
hardware directly or referenced by upper-layer software for packet filtering.
1.2 ACL Configuration Task List
Complete the following tasks to configure ACL:
Configuring Time Range
Configuring Basic ACL
Configuring Advanced ACL
Configuring Layer 2 ACL
Configuring User-defined ACL
Applying ACLs on Ports
Applying ACLs to a VLAN
1.2.1 Configuring Time Range
Time ranges can be used to filter packets. You can specify a time range for each rule in
an ACL. A time range-based ACL takes effect only in specified time ranges. Only after a
time range is configured and the system time is within the time range, can an ACL rule
take effect.
Two types of time ranges are available:
Periodic time range, which recurs periodically on the day or days of the week.
Absolute time range, which takes effect only in a period of time and does not recur.
Note:
An absolute time range on an H3C S5600 Series Ethernet Switches can be within the
range 1970/1/1 00:00 to 2100/12/31 24:00.
Task
1-4
Chapter 1 ACL Configuration
Remarks
Optional
Required
Required
Required
Required
Required
Required