Chapter5ServiceConguration
CommandFunction
zte(cfg)#clearingress-aclbasicnumber<1-99>ClearsabasicingressACL
instance.
zte(cfg)#configingress-aclextendnumber<100-199>Createsandconguresan
extendedportACLinstance.
zte(extend-acl-group)#rule<1-500>{permit|
deny}<ip-protocol>{<source-ipaddr><sip-mask>|any}{<des
tination-ipaddr><dip-mask>|any}[dscp<0-63>][fragment]
Setstherulethatanextended
ingressACLisusedtomatch
speciedeldsofIPv4packets.
zte(extend-acl-group)#rule<1-500>{permit|deny}icmp
{<source-ipaddr><sip-mask>|any}{<destination-ipaddr><dip-mask>|
any}[icmp-type<0-254><icmp-code>][dscp<0-63>][fragment]
Setstherulethatanextended
ingressACLisusedtomatch
ICMPpackets.
zte(extend-acl-group)#rule<1-500>{permit|deny}ip
{<source-ipaddr><sip-mask>|any}{<destination-ipaddr><dip-mask>|
any}[dscp<0-63>][fragment]
Setstherulethatanextended
ingressACLisusedtomatchIP
packets.
zte(extend-acl-group)#rule<1-500>{permit|deny}
tcp{<source-ipaddr><sip-mask>|any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|
any}[dest-port<0-65535><dport-mask>][establishing|
established][dscp<0-63>][fragment]
Setstherulethatanextended
ingressACLisusedtomatchTCP
packets.
zte(extend-acl-group)#rule<1-500>{permit|deny}
udp{<source-ipaddr><sip-mask>|any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|
any}[dest-port<0-65535><dport-mask>][dscp<0-63>][fragment]
Setstherulethatanextended
ingressACLisusedtomatchUDP
packets.
zte(extend-acl-group)#rule<1-500>{permit|deny}arp
{<sender-ipaddr><sip-mask>|any}{<target-ipaddr><tip-mask>|any}
Setstherulethatanextended
ingressACLisusedtomatchARP
packets.
zte(cfg)#clearingress-aclextendnumber<100-199>ClearsanextendedportACL
instance.
zte(cfg)#configingress-acllinknumber<200-299>Createsandconguresalayer-2
ingressACLinstance.
zte(link-acl-group)#rule<1-500>{permit|deny}ip{[cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]}
Setstherulethatalayer-2ingress
ACLisusedtomatchIPpackets.
zte(link-acl-group)#rule<1-500>{permit|deny}arp{[cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]}
Setstherulethatalayer-2ingress
ACLisusedtomatchARP
packets.
zte(link-acl-group)#rule<1-500>{permit|deny}other
{[ether-type<1501-65535>|dsap-ssap<0-65535>][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]}
Setstherulethatalayer-2ingress
ACLisusedtomatchpackets
exceptIP/ARPpackets.
5-45
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential