Chapter8ACLConguration
CongurationData
Table8-3liststhecongurationdataofthelayer-2ACL.
Table8-3CongurationDataoftheLayer-2ACL
ItemData
ACLnumber200
Rule1Action:deny
SourceMACaddress:0000.0000.0001
Protocoltype:any
Rule2Permitanytrafc
Interfacegei_1/21/1
Steps
1.Inglobalcongurationmode,createalayer-2ACL.
ZXAN(config)#acllinknumber200
ZXAN(config-link-acl)#
Note:
ThelayerACLnumberrangesfrom200to299.Alayer-2ACLcanbeappliedtothe
EthernetinterfaceandEPON-OLTinterface.
2.ConguretheACLrules.
ZXAN(config-link-acl)#rule1denyanyingress0000.0000.00010000.0000.0000
egressany
ZXAN(config-link-acl)#rule2permitany
ZXAN(config-link-acl)#exit
Note:
Eachlayer-2ACLsupportsupto4096rules.
Ifthetimerangeisnotcongured,theruleisalwayseffective.
3.InEthernetinterfacecongurationmode,applytheACL.
ZXAN(config)#interfacegei_1/21/1
ZXAN(config-if)#ipaccess-group200in
4.(Optional)QuerytheACLconguration.
ZXAN(config-if)#showacl200
8-5
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential