Chapter4ServiceConguration
Guidelines
TheARPrulecanmatchsender-speciedIP ,anysenderIP ,destination-speciedIP ,
anydestinationIP ,coseld,VLANeld,source-speciedMAC,anysourceMAC,
destination-speciedMACandanydestinationMAC.Therulecanbeboundtooneorall
ports.
4.13.44ingress-aclglobalruletype-any
Purpose
ThiscommandsetstherulethattheglobalingressACLmatchesthenon-IPv6packet.
CommandMode
GlobalingressACLcongurationmode
Syntax
rule<1-500>{permit|deny}port{<1-28>|any}any{[ether-type<1501-65535>][cos<0-7
>][<vlan-id>[<vlan-mask>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|any]}
ParameterDescription
ParameterDescription
<1-16>Globalrulenumber.
permitIftheconditionmatches,accessispermitted.
denyIftheconditionmatches,accessisdenied.
<1-28>
Bindstheglobalruletoaport.Differentdeviceshavedifferent
portnumberranges.Inthesyntax,the2928Edeviceisusedas
anexample.
any(rst)Bindstheglobalruletoallports.
any(second)
Thisruleonlymatchesnon-IPv6packet.TheIPv6packetignores
thisrule.
ether-type<1501-65535>
Thisruleisonlyvalidforthepacketwithspeciedether-type.
Otherpacketsignorethisrule.Therangeofether-typeis1501
to65535.
cos<0-7>
Thisruleisonlyvalidforthecos-speciedmessage.Ignorethis
ruleforothermessages.Therangeofcosis0to7.
<vlan-id>
ThisruleisonlyvalidformessageswiththespeciedVLANID.
Ignorethisruleforothermessages.TheruleofVLANIDis1
to4094.
<vlan-mask>OptionalVLANmask.Thedefaultvalueis0xfff.
4-257
SJ-20130731155059-003|2013-11-27(R1.0)ZTEProprietaryandCondential