Chapter8ACLConguration
Note:
EachstandardACLsupportsupto127rules.
Ifthetimerangeisnotcongured,theruleisalwayseffective.
4.InEthernetinterfacecongurationmode,applytheACL.
ZXAN(config)#interfacegei_1/21/1
ZXAN(config-if)#ipaccess-group3in
5.(Optional)QuerytheACLconguration.
ZXAN(config-if)#showacl3
aclstandardnumber3
rule1deny168.1.1.00.0.0.255time-rangeworktime
rule2permitany
6.(Optional)QuerytheinterfaceboundwiththeACL.
ZXAN(config-if)#showaccess-listbound
InterfaceDirectionTypeStatusAclnumber/name
gei_1/21/1inV4STDsuccessful3
–EndofSteps–
8.2ConguringanExtendedACL
ThissectiondescribeshowtocongureanextendedACLandapplyittoanEthernet
interface.
CongurationData
Table8-2liststhecongurationdataoftheextendedACL.
Table8-2CongurationDataoftheExtendedACL
ItemData
ACLnumber101
Rule1Action:deny
Sourceaddress:192.168.1.0/24
Protocoltype:TCP ,T elnet
Rule2PermitanyTCPandtelnettrafc
Interfacegei_1/21/1
Steps
1.Inglobalcongurationmode,createanextendedACL.
8-3
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential