ZXR105250SeriesCommandReference
ParameterDescription
dscp<0-63>
ThisruleisonlyvalidforthemessagewiththespeciedDSCP
value.Ignorethisruleforothermessages.TherangeofDSCP
valueis0to63.
fragment
Thisruleisonlyvalidforfragmentmessages.Fornon-fragment
messages,thisruleisignored.
cos<0-7>
Thisruleisonlyvalidforthecos-speciedmessage.Ignorethis
ruleforothermessages.Therangeofcosis0to7.
<vlan-id>
ThisruleisonlyvalidformessageswiththespeciedVLANID.
Ignorethisruleforothermessages.TheruleofVLANIDis1
to4094.
<vlan-mask>OptionalVLANmask.Thedefaultvalueis0xfff.
<source-mac>SourceMACaddressofthetransmittedpacket.
<smac-mask>SourceMACmask.
any(fourth)
TheanykeywordisusedastheabbreviationofsourceMAC
address00.00.00.00.00.00andmask00.00.00.00.00.00.
<dest-mac>DestinationMACaddressofthetransmittedpacket.
<dmac-mask>DestinationMACaddressofthetransmittedpacket.
any(fth)
Theanykeywordisusedastheabbreviationofthedestination
MACaddress00.00.00.00.00.00andmask00.00.00.00.00.00.
Guidelines
TheIPrulecanmatchsource-speciedIPs,anysourceIPs,destination-speciedIPs,any
destinationIPs,DSCPelds,IPfragmentelds,coselds,VLANelds,source-specied
MACs,anysourceMACs,destination-speciedMACs,andanydestinationMACs.The
rulecanbeboundtooneorallports.
4.13.41ingress-aclglobalruletype-tcp
Purpose
ThiscommandsetstherulethattheglobalingressACLmatchestheIPv4-TCPpacket.
CommandMode
GlobalingressACLcongurationmode
Syntax
rule<1-500>{permit|deny}port{<1-28>|any}tcp{<source-ipaddr><sip-mask>|any}[source-
port<0-65535><sport-mask>]{<destination-ipaddr><dip-mask>|any}[dest-port<0-65535><d
4-252
SJ-20131111172707-003|2013-11-27(R1.0)ZTEProprietaryandCondential