Zte ZXR10 2910E-PS Configuration Manual page 92

Zxr10 2900e series easy-maintenance secure switch
Hide thumbs Also See for ZXR10 2910E-PS:
Table of Contents

Advertisement

ZXR10 2900E Series Configuration Guide
Command
zte(hybrid-acl-group)#rule <1-500>{permit | deny} all
zte(cfg)#clear ingress-acl hybrid number <300-399>
zte(cfg)#config ingress-acl global
zte(global-acl-group)#rule <1-16>{permit | deny} port {<1-28>|
any}<ip-protocol>{<source-ipaddr><sip-mask>| any}{<destina
tion-ipaddr><dip-mask>| any}[dscp <0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>| any]
zte(global-acl-group)#rule <1-500>{permit | deny} port {<1-28>| any}
ip {<source-ipaddr><sip-mask>| any}{<destination-ipaddr><dip-mask>|
any}[dscp <0-63>][fragment][cos <0-7>][<vlan-id>[<vlan-mask>]][<source-
mac><smac-mask>| any][<dest-mac><dmac-mask>| any]
zte(global-acl-group)#rule <1-500>{permit | deny} port {<1-
28>| any} tcp {<source-ipaddr><sip-mask>| any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|
any}[dest-port <0-65535><dport-mask>][dscp <0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>| any]
zte(global-acl-group)#rule <1-500>{permit | deny} port {<1-28>|
any} udp {<source-ipaddr><sip-mask>| any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|
any}[dest-port <0-65535><dport-mask>][dscp <0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>| any]
zte(global-acl-group)#rule <1-500>{permit | deny} port {<1-28>| any}
arp {<sender-ipaddr><sip-mask>| any}{<target-ipaddr><tip-mask>|
any}[cos <0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>| any]
zte(global-acl-group)#rule <1-500>{permit | deny} port {<1-28>| any} any
{[ether-type <1501-65535>][cos <0-7>][<vlan-id>[<vlan-mask>]][<source-m
ac><smac-mask>| any][<dest-mac><dmac-mask>| any]}
zte(cfg)#config egress-acl basic number < 400-499>
zte(egress-basic-acl)#rule < 1-500>{ permit | deny}{< source-ipaddr><
sip-mask>| any}[ fragment]
zte(cfg)#clear egress-acl basic number < 400-499>
SJ-20120409144109-002|2012-07-02(R1.0)
Function
Sets the rule that a hybrid ingress ACL
is used to match any packet.
Clears a hybrid ingress ACL instance.
Enters and configures a global ingress
ACL instance.
Sets the rule that a global ingress ACL
matches IPv4–specified protocol field
packet.
Sets the rule that a global ingress ACL
matches IPv4 packet.
Sets the rule that a global ingress ACL
matches IPv4–TCP packet.
Sets the rule that a global ingress ACL
matches IPv4–UDP packet.
Sets the rule that a global ingress ACL
is used to match ARP packet.
Sets the rule that a global ingress ACL
is used to match non IPv6 packet.
Creates a basic egress ACL instance
and configures it.
Sets a basic egress ACL.
Clears a basic egress ACL instance.
4-46
ZTE Proprietary and Confidential

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents