ZXR102900ESeriesCongurationGuide
CommandFunction
zte(extend-acl-group)#rule<1-500>{permit|deny}
tcp{<source-ipaddr><sip-mask>|any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|
any}[dest-port<0-65535><dport-mask>][establishing|
established][dscp<0-63>][fragment]
Setstherulethatanextended
ingressACLisusedtomatchTCP
packets.
zte(extend-acl-group)#rule<1-500>{permit|deny}
udp{<source-ipaddr><sip-mask>|any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|
any}[dest-port<0-65535><dport-mask>][dscp<0-63>][fragment]
Setstherulethatanextended
ingressACLisusedtomatchUDP
packets.
zte(extend-acl-group)#rule<1-500>{permit|deny}arp
{<sender-ipaddr><sip-mask>|any}{<target-ipaddr><tip-mask>|any}
Setstherulethatanextended
ingressACLisusedtomatchARP
packets.
zte(cfg)#clearingress-aclextendnumber<100-199>ClearsanextendedportACL
instance.
zte(cfg)#configingress-acllinknumber<200-299>Createsandconguresalayer-2
ingressACLinstance.
zte(link-acl-group)#rule<1-500>{permit|deny}ip{[cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]}
Setstherulethatalayer-2ingress
ACLisusedtomatchIPpackets.
zte(link-acl-group)#rule<1-500>{permit|deny}arp{[cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]}
Setstherulethatalayer-2ingress
ACLisusedtomatchARP
packets.
zte(link-acl-group)#rule<1-500>{permit|deny}other
{[ether-type<1501-65535>|dsap-ssap<0-65535>][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]}
Setstherulethatalayer-2ingress
ACLisusedtomatchpackets
exceptIP/ARPpackets.
zte(link-acl-group)#rule<1-500>{permit|deny}any[cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethatalayer-2ingress
ACLisusedtomatchpacketswith
speciedcos,VLANid,smac,and
dmacags.
zte(cfg)#clearingress-acllinknumber<200-299>Clearsalayer-2ingressACL
instance.
zte(cfg)#configingress-aclhybridnumber<300-399>Createsandconguresahybrid
ingressACLinstance.
zte(hybrid-acl-group)#rule<1-500>{permit|
deny}<ip-protocol>{<source-ipaddr><sip-mask>|any}{<des
tination-ipaddr><dip-mask>|any}[dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethatahybridingress
ACLisusedtomatchspecied
eldsofIPv4packets.
5-46
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential