ZXR102900ESeriesCongurationGuide
CommandFunction
zte(hybrid-acl-group)#rule<1-500>{permit|
deny}ipv6icmp{<source-ipv6addr><sipv6-mask>|
any}[<destination-ipv6addr><dipv6-mask>|any][<vlan-id>]
Setstherulethatahybridingress
ACLisusedtomatchIPv6ICMP
packets.
zte(hybrid-acl-group)#rule<1-500>{permit|deny}allSetstherulethatahybridingress
ACLisusedtomatchanypacket.
zte(cfg)#clearingress-aclhybridnumber<300-399>ClearsahybridingressACL
instance.
zte(cfg)#configingress-acluser-definenumber<801-828>
Createsandconguresa
user-denedingressACL
instance.
zte(ingress-user-define-acl)#rule<1-500>{permit|
deny}[udb1<udb-value><udb-mask>][udb2<udb-value><
udb-mask>][udb3<udb-value><udb-mask>][udb4<udb-value><
udb-mask>][udb5<udb-value><udb-mask>][udb6<udb-value><
udb-mask>][udb7<udb-value><udb-mask>][udb8<udb-value><
udb-mask>][udb9<udb-value><udb-mask>][udb10<udb-value><
udb-mask>][udb11<udb-value><udb-mask>][udb12
<udb-value><udb-mask>][udb13<udb-value><udb-mask>][
udb14<udb-value><udb-mask>][udb15<udb-value><udb-mask>]
Denesaruleinauser-dened
ingressACL.
zte(cfg)#clearingress-acluser-definenumber<801-828>
Deletesauser-denedingress
ACLinstance.
zte(cfg)#configingress-aclglobalEntersandconguresaglobal
ingressACLinstance.
zte(global-acl-group)#rule<1-16>{permit|deny}port
{<1-28>|any}<ip-protocol>{<source-ipaddr><sip-mask>|any}{<d
estination-ipaddr><dip-mask>|any}[dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethataglobalingress
ACLmatchesspeciedeldsof
IPv4packets.
zte(global-acl-group)#rule<1-500>{permit|deny}port
{<1-28>|any}ip{<source-ipaddr><sip-mask>|any}{<destina
tion-ipaddr><dip-mask>|any}[dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethataglobalingress
ACLmatchesIPv4packets.
zte(global-acl-group)#rule<1-500>{permit|deny}port
{<1-28>|any}tcp{<source-ipaddr><sip-mask>|any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|any}[d
est-port<0-65535><dport-mask>][dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethataglobalingress
ACLmatchesIPv4–TCPpackets.
5-48
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential