Chapter 85 Access Control
OLT2406 User’s Guide
625
85.14 ONT ACL Commands
Use these commands to create ACL profiles for ONTs.
Table 330 Remote Management Commands
COMMAND DESCRIPTION M P
ont-acl-profile <profile-name>
Creates an ACL profile.
profile-name: less than 31 printable characters
C13
inactive Disables the ACL profile. C 13
no inactive Enables the ACL profile. C 13
no interface Restores the interface default setting for the ACL
profile.
C13
policy <drop|trust> Specifies the actions for the ACL profile.
drop: Discards the incoming packets.
trust: Forwards the incoming packets.
C13
no policy Restores the policy default setting for the ACL
profile.
C13
interface <lan|wan|both> Configures the interface(s) for the ACL profile. C 13
ip-protocol <protocol> Enters an IP protocol for the ACL profile.
See Table 331 on page 626 for the list of IP
protocol numbers.
protocol: 0 ~ 255
C13
no ip-protocol Removes the IP protocol for the ACL profile. C 13
counter <enable|disable> Enables or disables packet counting for the ACL
profile.
C13
logging <enable|disable> Enables or disables packet logging for the ACL
profile.
C13
src-mac-addr <mac> Specifies a source MAC address range.
mac: 00:00:00:00:00:00 ~ FF:FF:FF:FF:FF:FF
C13
dest-mac-addr <mac> Specifies a destination MAC address range.
mac: 00:00:00:00:00:00 ~ FF:FF:FF:FF:FF:FF
C13
src-ip-addr <ip> mask-bits <mask> Specifies the mask bits of the source IP address,
0-32.
C13
dest-ip-addr <ip> mask-bits <mask> Specifies the mask bits of the destination IP
address, 0-32.
C13
src-l4-port <port> Specifies a layer 4 source port.
port: 0-65535
C13
dest-l4-port <port> Specifies a layer 4 destination port.
port: 0-65535
C13
no src-mac-addr Removes the source MAC setting. C 13
no dest-mac-addr Removes the destination MAC setting. C 13
no src-ip-addr Removes the source IP address setting. C 13
no dest-ip-addr Removes the destination IP address setting. C 13
no src-l4-port Removes the source L4 port setting. C 13
no dest-l4-port Removes the destination L4 port setting. C 13