Chapter4ServiceConguration
ParameterDescription
fragment
ThisruleisonlyvalidforthemessagewiththespeciedDSCP
value.Ignorethisruleforothermessages.TherangeofDSCP
valueis0to63.
cos<0-7>
Thisruleisonlyvalidforthecos-speciedmessage.Ignorethis
ruleforothermessages.Therangeofcosis0to7.
<vlan-id>
ThisruleisonlyvalidformessageswiththespeciedVLANID.
Ignorethisruleforothermessages.TheruleofVLANIDis1
to4094.
<vlan-mask>OptionalVLANmask.Thedefaultvalueis0xfff.
<source-mac>SourceMACaddressofthetransmittedpacket.
<smac-mask>SourceMACmask.
any(fourth)
TheanykeywordisusedastheabbreviationofsourceMAC
address00.00.00.00.00.00andmask00.00.00.00.00.00.
<dest-mac>DestinationMACaddressofthetransmittedpacket.
<dmac-mask>DestinationMACmask.
any(fth)
TheanykeywordisusedastheabbreviationofdestinationMAC
address00.00.00.00.00.00andmask00.00.00.00.00.00.
Guidelines
TheTCPrulecanmatchsource-speciedIPs,anysourceIPs,TCPsourceportnumbers,
destination-speciedIPs,anydestinationIPs,TCPdestinationportnumbers,DSCPelds,
IPfragmentelds,coselds,VLANelds,source-speciedMACs,anysourceMACs,
destination-speciedMACs,andanydestinationMACs.Therulecanbeboundtooneor
allports.
4.13.42ingress-aclglobalruletype-udp
Purpose
ThiscommandsetstherulethattheglobalingressACLmatchestheIPv4-UDPpacket.
CommandMode
GlobalingressACLcongurationmode
Syntax
rule<1-500>{permit|deny}port{<1-28>|any}udp{<source-ipaddr><sip-mask>|
any}[source-port<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|any}[dest-port
<0-65535><dport-mask>][dscp<0-63>][fragment][cos<0-7>][<vlan-id>[<vlan-mask>]][<sour
ce-mac><smac-mask>|any][<dest-mac><dmac-mask>|any]
4-253
SJ-20130731155059-003|2013-11-27(R1.0)ZTEProprietaryandCondential