1-19
Parameters Type Function Description
lsap lsap-code
lsap-wildcard
lsap field
Specifies the lsap
field for the ACL rule
lsap-code: Encapsulation
format of data frames, a
16-bit hexadecimal
number.
lsap-wildcard: Mask of the
lsap value, a 16-bit
hexadecimal number used
to specify the mask bits.
source
{ source-mac-addr
source-mac-mask |
vlan-id }*
Source MAC address
information or source
VLAN information
Specifies the source
MAC address range
or source VLAN ID for
the ACL rule
source-mac-addr: Source
MAC address, in the
format of H-H-H.
source-mac-mask: Mask
of the source MAC
address, in the format of
H-H-H.
vlan-id: Source VLAN ID,
in the range of 1 to 4,094.
dest dest-mac-addr
dest-mac-mask
Destination MAC
address information
Specifies the
destination MAC
address range for the
ACL rule
dest-mac-addr:
Destination MAC address,
in the format of H-H-H.
dest-mac-mask: Mask of
the destination MAC
address, in the format of
H-H-H.
cos cos
Priority
Specifies the 802.1p
priority of the rule
cos: VLAN priority, in the
range of 0 to 7.
c-tag-vlan
c-tag-vlan-begin [ to
c-tag-vlan-end ]
Inner VLAN
information
Specifies information
about inner VLAN of
the rule
c-tag-vlan-begin,
c-tag-vlan-end: VLAN ID,
in the range of 1 to 4094.
This keyword and
argument combination is
usually used in
cooperation with the QinQ
function. For information
about QinQ, refer to
VLAN-VPN Operation.
time-range
time-name
Time range
information
Specifies the time
range in which the
rule takes effect.
time-name: specifies the
name of the time range in
which the rule is active; a
string comprising 1 to 32
characters.
type protocol-type
protocol-mask
Protocol type of
Ethernet frames
Specifies the protocol
type of Ethernet
frames for the ACL
rule
protocol-type: Protocol
type.
protocol-mask: Protocol
type mask.
When layer 2 ACLs are applied to ports or VLANs of the H3C S3600 series Ethernet switches, rules
configured with the format-type argument and the lsap keyword are invalid.