ZXR105250SeriesCongurationGuide
CommandFunction
zte(link-acl-group)#rule<1-500>{permit|deny}any[cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethatalayer-2ingress
ACLisusedtomatchpacketswith
speciedcos,VLANid,smac,and
dmacags.
zte(cfg)#clearingress-acllinknumber<200-299>Clearsalayer-2ingressACL
instance.
zte(cfg)#configingress-aclhybridnumber<300-399>Createsandconguresahybrid
ingressACLinstance.
zte(hybrid-acl-group)#rule<1-500>{permit|
deny}<ip-protocol>{<source-ipaddr><sip-mask>|any}{<des
tination-ipaddr><dip-mask>|any}[dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethatahybridingress
ACLisusedtomatchspecied
eldsofIPv4packets.
zte(hybrid-acl-group)#rule<1-500>{permit|deny}ip
{<source-ipaddr><sip-mask>|any}{<destination-ipaddr><dip-mask>|
any}[dscp<0-63>][fragment][cos<0-7>][<vlan-id>[<vlan-mask
>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|any]
Setstherulethatahybridingress
ACLisusedtomatchIPv4
packets.
zte(hybrid-acl-group)#rule<1-500>{permit|deny}tcp
{<source-ipaddr><sip-mask>|any}[source-port<0-65535><s
port-mask>]{<destination-ipaddr><dip-mask>|any}[dest-port
<0-65535><dport-mask>][dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethatahybridingress
ACLisusedtomatchIPv4-TCP
packets.
zte(hybrid-acl-group)#rule<1-500>{permit|deny}udp
{<source-ipaddr><sip-mask>|any}[source-port<0-65535><s
port-mask>]{<destination-ipaddr><dip-mask>|any}[dest-port
<0-65535><dport-mask>][dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethatahybridingress
ACLisusedtomatchIPv4-UDP
packets.
zte(hybrid-acl-group)#rule<1-500>{permit|deny}arp
{<sender-ipaddr><sip-mask>|any}{<target-ipaddr><tip-mask>|
any}[cos<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-m
ask>|any][<dest-mac><dmac-mask>|any]
Setstherulethatahybridingress
ACLisusedtomatchARP
packets.
zte(hybrid-acl-group)#rule<1-500>{permit|deny}any
{[ether-type<1501-65535>][cos<0-7>][<vlan-id>[<vlan-mask
>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|
any]}
Setstherulethatahybridingress
ACLisusedtomatchnon-IPv6
packets.
zte(hybrid-acl-group)#rule<1-500>{permit|deny}
ipv6<ip-protocol>{<source-ipv6addr><sipv6-mask>|
any}[<destination-ipv6addr><dipv6-mask>|any][<vlan-id>]
Setstherulethatahybridingress
ACLisusedtomatchspecied
eldsofIPv6packets.
5-46
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential