ZXR10CommandManual(SecurityVolume)
bootpc,bootps,domain,NTP ,pim-auto-rp,RIP ,SNMP ,sn-
mptrapandTFTP
�Ifthetime-rangeeldisnotcongured,thisrulewillbeeffec-
tivepermanently.Therelevanttimerangecommandmustbe
conguredbeforetheuseofthetime-rangeeld.
�ACLruleeventlistisonlysupportedinT160Gseriesswitches.
ExampleThisexampledescribeshowtocongurerules1~5oftheex-
tendedACL.
ZXR10(config)#aclextendednumber100
ZXR10(config-ext-acl)#rule1permit100anyany
ZXR10(config-ext-acl)#rule2permiticmp168.1.1.00.0.0.255any
echodscp1
ZXR10(config-ext-acl)#rule3denyipany168.1.0.00.0.255.255
tos1precedence1
ZXR10(config-ext-acl)#rule4permittcpanyeqbgp168.1.1.0
0.0.0.255eqdomainestablishedtos1precedence7
ZXR10(config-ext-acl)#rule5denyudpanyanydscp5time-rangetest
Related
Commands
showacl
time-range
event-list
rule(Layer2ACL)
PurposeUsethiscommandtodenealayer2ACLrule.Deletetherule
withnocommand.
CommandModesLayer2ACLconguration
Syntaxrule<rule-no>{permit|deny}{<ether-protocol>|any}[cos
<cos-value>][incos<cos-value>][dinvlan<vlan-id>][douterv
lan<vlan-id>][ingress{<source-mac><source-mac-wildcard>|
any}][egress{<dest-mac><dest-mac-wildcard>|any}][{time
-range<timerange-name>|event<event-name>}]
norule<rule-no>
Syntax
Description
<rule-no>ACLrulenumber ,range:1~100or1000
permitPermitsthepacketthatmatchesthisrule
denyDeniesthepacketthatmatchesthisrule
<ether-protocol>
Ethernettypeeld,IP ,ARPoradesignated
number(0~65535)
cos<cos-value>
802.1ppriority,range:0~7,outer
incos<cos-value>802.1ppriority,range:0~7,inside
dinvlan<vlan-id>
InsideVLANidentier
doutervlan
<vlan-id>
OutsideVLANidentier
ingressFiltersaccordingtosourceMACaddress
28CondentialandProprietaryInformationofZTECORPORATION