Chapter4ServiceConguration
sourceportnumber,UDPdestinationportnumber,ICMPtype,ICMPCodeand
DiffServCodePoint(DSCP).
8.L2egressACL:MatchdestinationMACaddress,sourceVLANIDand802.1p
priorityvalue,EthernetnetworktypeandDSAP/SSAP .
9.HybridegressACL:MatchSourceIPv4/IPv6address,destinationIPv4/IPv6
address,IPprotocoltype,TCPsourceportnumber,TCPdestinationportnumber,
UDPsourceportnumber,UDPdestinationportnumber,DiffServCodePoint
(DSCP),sourceMACaddress,destinationMACaddress,sourceVLANIDand
802.1ppriorityvalue.
lEachACLhasanaccesslistnumbertoidentify.Theaccesslistnumberisanumber.
TheaccesslistnumberrangesofdifferenttypesofACLareshownbelow:
1.BasicingressACL:1~99
2.ExtendedingressACL:100~199
3.L2ingressACL:200~299
4.HybridingressACL:300~399,supportIPv6
5.BasicegressACL:400~499
6.ExtendedegressACL:500~599
7.L2egressACL:600-699
8.HybridegressACL:700~799,supportsIPv6
9.GlobalACL:800
lEachACLhasatmost500rulesandtherangeis1-500.
ConguringACL
TheACLcongurationincludesthefollowingcommands:
CommandFunction
zte(cfg)#setport<portlist>aclmode{port|vlan}SetsportACLbindingmode.
zte(cfg)#setport<portlist>acl<1-799>{enable|disable}BindsACLinstancetotheport.
zte(cfg)#setvlan<vlanlist>acl<1-399>{enable|disable}BindsACLinstancetotheVLAN.
zte(cfg)#setacl<1-799>rule<1-500>time-range<word>{enable|disable}
ExecutesanACLactioninaspecic
timerange.
zte(cfg)#createacl<1-800>name<name>CreatesanACLname.
zte(cfg)#clearacl-name<1-800>ClearsanACLname.
zte(cfg)#showport<portlist>acl-modeDisplaysportACLbindingmode.
zte(cfg)#configingress-aclbasicnumber<1-99>
Createsandconguresabasicingress
ACLinstance.
zte(basic-acl-group)#rule<1-500>{permit|deny}{<source-ipaddr><sip-ma
sk>|any}[fragment]
SetsabasicingressACLrule.
zte(cfg)#clearingress-aclbasicnumber<1-99>ClearsabasicingressACLinstance.
zte(cfg)#configingress-aclextendnumber<100-199>
Createsandconguresanextended
portACLinstance.
4-43
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandCondential