Activating An Acl - 3Com Switch 7700 Configuration Manual

Switch
Hide thumbs Also See for Switch 7700:
Table of Contents

Advertisement

236
C
7: Q
S/ O
HAPTER
O
PERATION

Activating an ACL

Perform the following configuration in the designated view.
Table 6 Define Layer-2 ACL
Operation
Enter Layer-2 ACL view (from system view)
Add a sub-item to the ACL (from Layer-2 ACL
view)
Delete a sub-item from the ACL (from Layer-2
ACL view)
Delete one ACL or all the ACL (from system
view)
A Layer-2 ACL can be identified with numbers ranging from 4000 to 4999.
If you assign an ACL to an interface and then make changes to the ACL, you must
reassign the ACL to the interface before the changes to the ACL will apply on the
interface.
A defined ACL can be active after being enabled globally on the switch. This
function is used to activate ACL filtering or to classify the data transmitted by the
hardware of the switch.
Perform the following configuration in Qos view.
Table 7 Activate ACL
Operation
Activate an ACL
Deactivate an ACL
ARP packets are always permitted to pass through the switch. You can't use the
packet-filter command to filter ARP packets.
See the Switch 7700 Command Reference Guide for additional details.
Displaying and Debugging an ACL
After you configure an ACL, execute the display command in all views to display
the ACL configuration, and to verify the effect of the configuration. Execute the
reset command in user view to clear the statistics of the ACL module.
Table 8 Display and Debug ACL
Operation
Display the status of the time range
Command
acl { number acl-number | name acl-name
link } [ match-order { config | auto } ]
rule [ rule-id ] { permit | deny } [
protocol-type ] [ format-type ] ingress { {
source-vlan-id | source-mac-addr }| any }
egress { [ dest-mac-addr | any }] [ time-range
name ]
undo rule rule-id
undo acl { number acl-number | name
acl-name | all }
Command
packet-filter inbound { ip-group {
acl-number | acl-name } [ rule rule ] |
link-group { acl-number | acl-name } [ rule
rule ] } [ not-care-for-interface ]
undo packet-filter inbound { ip-group {
acl-number | acl-name } [ rule rule ] |
link-group { acl-number | acl-name } [ rule
rule ] } [ not-care-for-interface ]
Command
display time-range [ all | name ]

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents