Chapter5ServiceConguration
CommandFunction
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}tcp{<
source-ipaddr><sip-mask>|any}[ssourrce-porrtt<0-65535><
sport-mask>]{<destination-ipaddr><dip-mask>|any}[desstt-porrtt
<0-65535><dport-mask>][dsscp<0-63>][fragment][coss
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
SetsahybridegressACLthat
matchesIPv4-TCPpackets.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}udp{<
source-ipaddr><sip-mask>|any}[ssourrce-porrtt<0-65535><
sport-mask>]{<destination-ipaddr><dip-mask>|any}[desstt-porrtt
<0-65535><dport-mask>][dsscp<0-63>][fragment][coss
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
SetsahybridegressACLthat
matchesIPv4-UDPpacket.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}arp
{<sender-ipaddr><sip-mask>|any}{<target-ipaddr><tip-mask>|
any}[coss<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><
smac-mask>|any][<dest-mac><dmac-mask>|any]
SetsahybridegressACLthat
matchesARPpackets.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}any
{[ettherr-ttype<1501-65535>][coss<0-7>][<vlan-id>[<
vlan-mask>]][<source-mac><smac-mask>|any][<dest-mac><
dmac-mask>|any]}
SetsahybridegressACLthat
matchesnon-IPv6packet
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}
iipv6<ip-protocol>{<source-ipv6addr><sipv6-mask>|any}[<
destination-ipv6addr><dipv6-mask>|any][<vlan-id>]
SetsahybridegressACLthat
matchesspeciedeldsofIPv6
packets.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}ipv6
tcp{<source-ipv6addr><sipv6-mask>|any}[ssourrce-porrtt<
0-65535><sport-mask>][<destination-ipv6addr><dipv6-mask>|
any][desstt-porrtt<0-65535><dport-mask>][<vlan-id>]
SetsahybridegressACLthat
matchesIPv6-TCPpackets.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}ipv6
udp{<source-ipv6addr><sipv6-mask>|any}[ssourrce-porrtt<
0-65535><sport-mask>][<destination-ipv6addr><dipv6-mask>|
any][desstt-porrtt<0-65535><dport-mask>][<vlan-id>]
SetsahybridegressACLthat
matchesIPv6-UDPpackets.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}ipv6any
{<source-ipv6addr><sipv6-mask>|any}[<destination-ipv6addr><
dipv6-mask>|any][<vlan-id>]
SetsahybridegressACLthat
matchesIPv6packets.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}allSetsahybridegressACLthat
matchesanypacket.
zte(cfg)#clearegress-aclhybridnumber<700-799>ClearsahybridegressACL
instance.
zte(cfg)#configingress-acluser-defineudb<1-15>anchor
<0-3>[offset<0-31>][data-length<1-6>]
Setsauser-denedanchorand
offset.
5-51
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential