l User-defined ACLs process data packets according to the rules defined by users.
The S7700 supports basic ACL6s and advanced ACL6s for IPv6 packets.
l A basic ACL6 can use the source IP address, fragmentation flag, and effective time range
as the elements of rules.
l An advanced ACL6 can use the source IP address and destination IP address of data packets,
protocol type supported by IP, features of the protocol such as the source port number and
destination port number, ICMPv6 protocol, and ICMPv6 Code as the elements of rules.
Create a traffic classifier based on an ACL.
Procedure
l Creating a traffic classifier based on a basic ACL
1. Run:
system-view
The system view is displayed.
2. Run:
acl [ number ] basic-acl-number [ match-order { auto | config } ]
A basic ACL is created and the ACL view is displayed.
Or, run:
acl [ ipv6 ] [ number ] basic-acl-number [ match-order { auto | config } ]
A basic ACL6 is created and the ACL6 view is displayed.
3. (Optional) Run:
step step-value
The step value between ACL rule IDs is set.
4. Run:
rule [ rule-id ] { deny | permit } [ fragment | source { source-address
source-wildcard | any } | time-range time-name ]
*
A basic ACL4 rule is created.
Or, run:
rule [ rule-id ] { deny | permit } [ fragment | source { source-ipv6-
address prefix-length | source-ipv6-address/prefix-length | source-ipv6-
address postfix postfix-length | any } | time-range time-name ]
*
A basic ACL6 rule is created.
5. Run:
quit
Return to the system view.
6. Run:
traffic classifier classifier-name [ operator { and | or } ] [ precedence
precedence-value ]
A traffic classifier is created and the traffic classifier view is displayed.
The and parameter indicates that the relationship between rules in a traffic classifier
is AND. That is, packets match a traffic classifier only when the packets match all
non-ACL rules and an ACL rule in the traffic classifier. The or parameter indicates
that the relationship between rules in a traffic classifier is OR. That is, packets match
a traffic classifier when the packets match a rule in the traffic classifier.
Quidway S7700 Smart Routing Switch
Configuration Guide - QoS 1 Class-based QoS Configuration
Issue 01 (2011-07-15) Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
16