ZXR105250SeriesCongurationGuide
CommandFunction
zte(global-acl-group)#rule<1-500>{permit|deny}port
{<1-28>|any}ip{<source-ipaddr><sip-mask>|any}{<destina
tion-ipaddr><dip-mask>|any}[dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethataglobalingress
ACLmatchesIPv4packets.
zte(global-acl-group)#rule<1-500>{permit|deny}port
{<1-28>|any}tcp{<source-ipaddr><sip-mask>|any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|any}[d
est-port<0-65535><dport-mask>][dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethataglobalingress
ACLmatchesIPv4–TCPpackets.
zte(global-acl-group)#rule<1-500>{permit|deny}port
{<1-28>|any}udp{<source-ipaddr><sip-mask>|any}[source-port
<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|any}[d
est-port<0-65535><dport-mask>][dscp<0-63>][fragment][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]
Setstherulethataglobalingress
ACLmatchesIPv4–UDPpackets.
zte(global-acl-group)#rule<1-500>{permit|deny}
port{<1-28>|any}arp{<sender-ipaddr><sip-mask>|
any}{<target-ipaddr><tip-mask>|any}[cos<0-7>][<vlan-id>[<vlan-
mask>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|
any]
Setstherulethataglobalingress
ACLisusedtomatchARP
packets.
zte(global-acl-group)#rule<1-500>{permit|deny}
port{<1-28>|any}any{[ether-type<1501-65535>][cos
<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|
any][<dest-mac><dmac-mask>|any]}
Setstherulethataglobalingress
ACLisusedtomatchnonIPv6
packets.
zte(cfg)#configegress-aclbasicnumber<400-499>CreatesabasicegressACL
instanceandconguresit.
zte(egress-basic-acl)#rule<1-500>{permit|deny}{<
source-ipaddr><sip-mask>|any}[fragment]
SetsabasicegressACL.
zte(cfg)#clearegress-aclbasicnumber<400-499>ClearsabasicegressACL
instance.
zte(cfg)#configegress-aclextendnumber<500-599>CreatesanextendedegressACL
instanceandconguresit.
zte(egress-extend-acl)#rule<1-500>{permit|
deny}<ip-protocol>{<source-ipaddr><sip-mask>|any}{<
destination-ipaddr><dip-mask>|any}[dsscp<0-63>][fragment]
SetsanextendedegressACLthat
matchesspeciedeldsofIPv4
packets.
5-48
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential