ZXR10CommandManual(SecurityVolume)
ACLruleeventlistisonlysupportedinT160Gseriesswitches.
ExampleThisexampledescribeshowtocongurerules1and10ofthe
basicACL.
ZXR10(config)#aclstandardnumber1
ZXR10(config-std-acl)#rule1permit168.1.1.10.0.0.255
ZXR10(config-std-acl)#rule10permitanytime-rangetest
Related
Commands
showacl
time-range
event-list
rule(ExtendedACL)
PurposeUsethiscommandtodeneanextendedACLrule.Deletetherule
withnocommand.
CommandModesExtendedACLconguration
SyntaxForZXR10seriesrouter ,
rule<rule-no>{permit|deny}permit<protocol><source><s
ource-wildcard>[<source-port>]<destination><destination-wild
card>[<destination-port>][log]
ForZXR10seriesEthernetswitch,
rule<rule-no>{permit|deny}icmp{<source><source-wildca
rd>|any}{<dest><dest-wildcard>|any}[<icmp-type>[icmp-c
ode<icmp-code>]][{[precedence<pre-value>][tos<tos-valu
e>]}|dscp<dscp-value>][fragment][{time-range<timerang
e-name>|event<event-name>}]
rule<rule-no>{permit|deny}{<ip-number>|ip}{<so
urce><source-wildcard>|any}{<dest><dest-wildcard>|
any}[{[precedence<pre-value>][tos<tos-value>]}|dscp
<dscp-value>][fragment][{time-range<timerange-name>|
event<event-name>}]
rule<rule-no>{permit|deny}tcp{<source><source-wildca
rd>|any}[<rule><port>]{<dest><dest-wildcard>|any}[<rul
e><port>][established][tcp-control<0-63>][{[precedence
<pre-value>][tos<tos-value>]}|dscp<dscp-value>][fragme
nt][{time-range<timerange-name>|event<event-name>}]
norule<rule-no>
Syntax
Description
<rule-no>ACLrulenumber ,range:1~100
permitPermitsthepacketthatmatchesthisrule
denyDeniesthepacketthatmatchesthisrule
<source>
SourceIPaddress
<source-wildcard>SourceIPaddresswildcardmask
<destination>DestinationIPaddress
26CondentialandProprietaryInformationofZTECORPORATION