3Com SuperStack 4 Configuration Manual page 196

5500g-ei family
Hide thumbs Also See for SuperStack 4:
Table of Contents

Advertisement

208
C
8: ACL C
HAPTER
ONFIGURATION
Table 225 Define Basic ACL
Operation
Enter basic ACL view (from System
View)
add a sub-item to the ACL (from
Basic ACL View)
delete a sub-item from the ACL (from
Basic ACL View)
Delete one ACL or all the ACL (from
System View)
Define Advanced ACL
The rules of the classification for advanced ACL are defined on the basis of the
attributes such as source and destination IP address, the TCP or UDP port number
in use and packet priority to process the data packets. The advanced ACL supports
the analysis of three types of packet priorities, ToS (Type of Service), IP and DSCP
priorities.
You can use the following command to define advanced ACL.
Perform the following configuration in the corresponding view.
Table 226 Define Advanced ACL
Operation
Enter advanced ACL view (from
System View)
Add a sub-item to the ACL (from
Advanced ACL View)
Delete a sub-item from the ACL
(from Advanced ACL View)
Delete one ACL or all the ACL
(from System View)
Note that, the port1 and port2 in the above command specify the TCP or UDP
ports used by various high-layer applications. For some common port numbers,
you can use the mnemonic symbols as a shortcut. For example, "bgp" can
represent the TCP number 179 used by BGP.
Define Layer-2 ACL
The rules of Layer-2 ACL are defined on the basis of the Layer-2 information such
as source MAC address, source VLAN ID, Layer-2 protocol type, Layer-2 packet
format and destination MAC address.
Command
acl number
acl_number
config | auto } ]
rule_id
rule [
] { permit | deny } [
source_addr wildcard
source {
fragment | logging | time-range
undo rule
rule_id
| logging | time-range ]*
undo acl { number
Command
acl number
acl_number
config | auto } ]
rule_id
rule [
] { permit | deny }
protocol
[ source {
any } ] [ destination {
| any } ] [ source-port
port2
] ] [ destination-port
port1
[
port2
] ] [ icmp-type
established ] [ [ { precedence
tos
dscp
tos
| dscp
instance
] | fragment | logging |
name
time-range
]*
rule_id
undo rule
[ source | destination |
source-port | destination-port |
icmp-type | precedence | tos | dscp |
fragment | logging | time-range |
vpn-instance ]*
acl_number
undo acl { number
[ match-order {
| any } |
name
[ source | fragment
acl_number
| all }
[ match-order {
source_addr wildcard
dest_addr wildcard
operator port1
operator
type code
] [
precedence
}* | vpn-instance
| all }
]*
|
[

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Superstack 4 5500g-ei series

Table of Contents