ZXR102900ESeriesCongurationGuide
lACLrulescanbeadded,deleted,andsorted.
1.RulescanbeaddedtoaconguredACL.RegularIDnumberrangeis1-500.
2.ConguredACLcanbedeletedregularly.IfthespeciedACLinstancenumber
orrulenumberisnotcongured,afalsemessagewillreturn.
3.ManyrulesofanACLcanbesorted.Itisnecessarytospecifythepositionwhere
arulenumbershouldbemoved.
lAnACLcanbecomevalidaccordingtotheconguredtimerange.Afterconguring
absoluteorrelativetimerangeontheswitch,thetimerangecanbeappliedtotherule
oftheACL.Thiscausestheruletobevalidaccordingtothetimerangespecication.
lTheZXR102900EprovidesthefollowingtentypesofACLs:
1.BasicACL:OnlymatchesthesourceIPaddress.
2.ExtendedACL:MatchesthesourceIPaddress,destinationIPaddress,IP
protocoltype,TCPsourceportnumber,TCPdestinationportnumber,UDP
sourceportnumber,UDPdestinationportnumber,ICMPtype,ICMPCodeand
DiffServCodePoint(DSCP).
3.L2ingressACL:MatchesthesourceMACaddress,destinationMACaddress,
sourceVLANIDand802.1ppriorityvalue,Ethernetnetworktypeand
DSAP/SSAP .
4.HybridingressACL:MatchessourceIPv4/IPv6address,destinationIPv4/IPv6
address,IPprotocoltype,TCPsourceportnumber,TCPdestinationportnumber,
UDPsourceportnumber,UDPdestinationportnumber,DiffServCodePoint
(DSCP),sourceMACaddress,destinationMACaddress,sourceVLANIDand
802.1ppriorityvalue.
5.GlobalACL:MatchesthesourceIPaddress,destinationIPaddress,IPprotocol
type,TCPsourceportnumber,TCPdestinationportnumber,UDPsourceport
number,UDPdestinationportnumber,DiffServCodePoint(DSCP),sourceMAC
address,destinationMACaddress,sourceVLANIDand802.1ppriorityvalue.
6.BasicegressACL:OnlymatchessourceIPaddress.
7.ExtendedegressACL:MatchesthesourceIPaddress,destinationIPaddress,
IPprotocoltype,TCPsourceportnumber,TCPdestinationportnumber,UDP
sourceportnumber,UDPdestinationportnumber,ICMPtype,ICMPCodeand
DiffServCodePoint(DSCP).
8.L2egressACL:MatchesthedestinationMACaddress,sourceVLANIDand802.
1ppriorityvalue,EthernetnetworktypeandDSAP/SSAP .
9.HybridegressACL:MatchestheSourceIPv4/IPv6address,destination
IPv4/IPv6address,IPprotocoltype,TCPsourceportnumber,TCPdestination
portnumber,UDPsourceportnumber,UDPdestinationportnumber,DiffServ
CodePoint(DSCP),sourceMACaddress,destinationMACaddress,source
VLANIDand802.1ppriorityvalue.
10.User-denedingressACL:Onlymatchesthebytesdenedbyusers.
lEachACLhasanaccesslistnumbertoidentify,whichisadigit.Theaccesslist
numberrangesofdifferenttypesofACLareshownbelow:
1.BasicingressACL:1–99
2.ExtendedingressACL:100–199
3.L2ingressACL:200–299
5-44
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential