T3700G-28TQ
 
JetStream 28-Port Gigabit Stackable L3 Managed Switch CLI Guide 
 
198 
source-ip-mask  —— The source IP address mask. It is required if you typed 
the source IP address. 
destination-ip  ——  The destination IP address contained in the rule. 
destination-ip-mask  ——  The destination IP address mask. It is required if you 
typed the destination IP address. 
time-segment  ——  The time-range for the rule to take effect. By default, it is 
not limited. 
dscp  ——  Specify the dscp value, ranging from 0 to 63. 
s-port  ——  The source port number. 
d-port  ——  The destination port number. 
tcpflag  ——  Specify the flag value when using TCP protocol. 
protocol  ——  Configure the value of the matching protocol. 
tos——  Enter the IP ToS contained in the rule. 
pre  ——  Enter the IP Precedence contained in the rule. 
Command Mode 
Global Configuration Mode 
Example 
Create an Extended-IP ACL whose ID is 2220, and add Rule 10 for it. In the rule, 
the source IP address is 192.168.0.100, the source IP address mask is 
255.255.255.0, the time-range for the rule to take effect is tSeg1, and the 
packets match this rule will be forwarded by the switch: 
T3700G-28TQ(config)#access-list create 2220 
T3700G-28TQ(config)#access-list extended 2220  rule  10 permit sip 
192.168.0.100 smask 255.255.255.0 tseg tSeg1 
rule 
Description 
The  rule command is used to configure MAC ACL rule. To delete the 
corresponding rule, please use no rule command. 
Syntax 
rule rule-id {deny | permit} [smac source-mac smask source-mac-mask ] 
[dmac destination-mac dmask destination-mac-mask ] [type ethernet-type] [pri 
user-pri] [tseg time-segment]