Chapter2ACLConguration
egress
DestinationMACaddresskeyword
time-range
<timerange-name>
Timerangename,notmorethan31
characters
event<event-name>
Eventlistname,notmorethan31characters
Instructions�ZXR10T160Gsupportsthiscommand.
�ForTCPandv,theegresskeywordcannotbeconguredafter
theingresskeywordiscongured.IPisnotlimitedbyit.
�Timerangecanbeusedinthecommandonlyafterthetime
rangeiscongured.
�ACLruleeventlistisonlysupportedinT160Gseriesswitches.
ExampleThisexampledescribeshowtocongurerules1~3ofthehybrid
ACL.
ZXR10(config)#aclhybridnumber1
ZXR10(config-hybd-acl)#rule1permitipanyanyingress
0000.0000.32300000.0000.0000egressany
ZXR10(config-hybd-acl)#rule2denyudpany
168.1.1.10.0.0.0egress1111.0000.00000000.ffff.ffff
ZXR10(config-hybd-acl)#rule3permittcp168.1.1.10.0.0.255
eqftp168.1.2.20.0.0.255eqtelnet1024ingress
1111.aabb.cccc0000.0000.fffftime-rangetest
Related
Commands
showacl
time-range
event-list
rule(User-definedACL)
PurposeUsethiscommandtodenetheruleofuser-denedACL.Remove
thisrulewiththenoformofthiscommand.
CommandModesUser-denedACLcongurationmode
Syntaxrule<rule-no>permit|deny[any|[tag<tag-num>]<offset
rule-stringrule-mask>&<1~4>][{time-range<timerange-nam
e>|event<event-name>}]
norule<rule-no>
Syntax
Description
<rule-no>ACLrulenumber ,range:1~1000
permitPermitsthepacketthatmatchesthisrule
denyDeniesthepacketthatmatchesthisrule
<tag-num>
TagcontainedinthematchedVLANpackets,
optional,itis0ifitisnotcongured
<offset>Offsetbytes,basedonthepacketheader ,it
mustbe2+4*n(n=0,1,2,3)
CondentialandProprietaryInformationofZTECORPORATION31