Chapter4ServiceConguration
ParameterDescription
<dip-mask>
Destinationmaskusedfordestination.Itisa32-bitIPaddress
expressedindotteddecimalnotation.
any(second)
Theanykeywordisusedastheabbreviationofthedestination
0.0.0.0andthedestinationmask0.0.0.0.
dest-port<0-65535>
TCPdestinationportnumberofthetransmittedpacket
Theparametersofdest-portcanresolvethesomeknownport
numbers.Alsotheportnumberandmaskcanbedirectlyinputted.
<dport-mask>Destinationportnumbermask.
establishing
Thisruleisonlyvalidforthemessagesthatactivelyestablish
TCPconnections.Itmatchesagack=0,syn=1.Ignorethisrule
forothermessages.
established
Thisruleisonlyvalidforthemessagesthatpassivelyestablish
TCPconnections.Itmatchesagack=1,syn=1.Ignorethisrule
forothermessages.
dscp<0-63>
ThisruleisonlyvalidformessageswiththespeciedDSCPvalue.
Ignorethisruleforothermessages.TherangeofDSCPis0to63.
fragment
Thisruleisonlyvalidforfragmentmessages.Non–fragment
messagesignorethisrule.
Guidelines
TheTCPrulecanmatchTCPpacketswithspeciedsourceIPaddresses,anysource
IPaddress,specieddestinationIPaddresses,anydestinationIPaddress,TCPsource
portnumbers,TCPdestinationportnumbers,activeTCPlinks,passiveTCPlinks,DSCP
elds,orIPfragmentelds.
4.13.16ingress-aclextendruletype-udp
Purpose
ThiscommandsetstherulethattheextendedingressACLisusedtomatchUserDatagram
Protocol(UDP)messages.
CommandMode
ExtendedingressACLcongurationmode
Syntax
rule<1-500>{permit|deny}udp{<source-ipaddr><sip-mask>|any}[source-port<0-65535><s
port-mask>]{<destination-ipaddr><dip-mask>|any}[dest-port<0-65535><dport-mask>][dscp
<0-63>][fragment]
4-225
SJ-20131111172707-003|2013-11-27(R1.0)ZTEProprietaryandCondential