ZXR102900ESeriesCongurationGuide
CommandFunction
zte(cfg)#configegress-aclhybridnumber<700-799>
CreatesahybridegressACLinstance
andconguresit.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}<ip-protocol>{<
source-ipaddr><sip-mask>|any}{<destination-ipaddr><dip-mask>|any}[
dsscp<0-63>][fragment][coss<0-7>][<vlan-id>[<vlan-mask>]][<
source-mac><smac-mask>|any][<dest-mac><dmac-mask>|any]
SetsahybridegressACLwhich
matchestheprotocoleldofIPv4.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}ip{<source-ipaddr><
sip-mask>|any}{<destination-ipaddr><dip-mask>|any}[dsscp<0-63>][
fragment][coss<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><
smac-mask>|any][<dest-mac><dmac-mask>|any]
SetsahybridegressACLwhich
matchestheIPv4packet.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}tcp{<source-ipaddr><
sip-mask>|any}[ssourrce-porrtt<0-65535><sport-mask>]{<
destination-ipaddr><dip-mask>|any}[desstt-porrtt<0-65535><
dport-mask>][dsscp<0-63>][fragment][coss<0-7>][<vlan-id>[<
vlan-mask>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|
any]
SetsahybridegressACLwhich
matchestheIPv4-TCPpacket.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}udp{<source-ipaddr><
sip-mask>|any}[ssourrce-porrtt<0-65535><sport-mask>]{<
destination-ipaddr><dip-mask>|any}[desstt-porrtt<0-65535><
dport-mask>][dsscp<0-63>][fragment][coss<0-7>][<vlan-id>[<
vlan-mask>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|
any]
SetsahybridegressACLwhich
matchestheIPv4-UDPpacket.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}arp{<sender-ipaddr><
sip-mask>|any}{<target-ipaddr><tip-mask>|any}[coss<0-7>][<vlan-id>[<
vlan-mask>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|
any]
SetsahybridegressACLwhich
matchestheARPpacket.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}any{[ettherr-ttype
<1501-65535>][coss<0-7>][<vlan-id>[<vlan-mask>]][<source-mac><
smac-mask>|any][<dest-mac><dmac-mask>|any]}
SetsahybridegressACLwhich
matchesthenon-IPv6packet.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}iipv6<ip-protocol>{<
source-ipv6addr><sipv6-mask>|any}{<destination-ipv6addr><dipv6-mask>|
any}[<vlan-id>]
SetsahybridegressACLwhich
matchestheprotocoleldofIPv6.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}ipv6tcp{<
source-ipv6addr><sipv6-mask>|any}[ssourrce-porrtt<0-65535><
sport-mask>]{<destination-ipv6addr><dipv6-mask>|any}[desstt-porrtt<
0-65535><dport-mask>][<vlan-id>]
SetsahybridegressACLwhich
matchestheIPv6-TCPpacket.
zte(egress-hybrid-acl)#rule<1-500>{permit|deny}ipv6udp{<
source-ipv6addr><sipv6-mask>|any}[ssourrce-porrtt<0-65535><
sport-mask>]{<destination-ipv6addr><dipv6-mask>|any}[desstt-porrtt<
0-65535><dport-mask>][<vlan-id>]
SetsahybridegressACLwhich
matchestheIPv6-UDPpacket.
4-48
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandCondential