Chapter9ACLConguration
192.168.4.700.0.0.0time-rangeworking-time
ZXR10(config-ext-acl)#rule4denyipany192.168.3.1000.0.0.0
time-rangeworking-time
ZXR10(config-ext-acl)#rule5permitipanyany
/*DefineanextendedACLtolimittheusersofDepartmentB*/
ZXR10(config)#aclextendnumber101
ZXR10(config-ext-acl)#rule1permitip192.168.2.1000.0.0.0any
ZXR10(config-ext-acl)#rule2denyip192.168.2.00.0.0.255
192.168.4.600.0.0.0time-rangeworking-time
ZXR10(config-ext-acl)#rule3denytcpanyeq8888
192.168.4.700.0.0.0time-rangeworking-time
ZXR10(config-ext-acl)#rule4permitipanyany
/*ApplyACLstothecorrespondingphysicalports*/
ZXR10(config)#interfacefei_2/1
ZXR10(config-if)#ipaccess-group100in
ZXR10(config-if)#exit
ZXR10(config)#interfacefei_2/2
ZXR10(config-if)#ipaccess-group101in
ZXR10(config-if)#exit
ACLMaintenanceand
Diagnosis
TocongureACLmaintenanceanddiagnosis,performthefollow-
ingsteps.
Step
CommandFunction
1
ZXR10#showacl[<acl-number>|name<acl-name>]
Thisdisplaysthecontentsof
allACLsoroftheACLwith
speciedlistnumber
2
ZXR10#showrunning-configinterface<port-name>Thisdisplaystheconguration
informationofanEthernet
port
CondentialandProprietaryInformationofZTECORPORATION89