Chapter4ServiceConguration
4.13.38configingress-aclglobal
Purpose
ThiscommandenterstheglobalingressACLinstanceandcongurestheinstance.
CommandMode
Globalcongurationmode
Syntax
configingress-aclglobal
4.13.39ingress-aclglobalruletype-ip-protocol
Purpose
ThiscommandsetstherulethattheglobalingressACLmatchesthepacketwith
IPv4-speciedeld.
CommandMode
GlobalingressACLcongurationmode
Syntax
rule<1-16>{permit|deny}port{<1-28>|any}<ip-protocol>{<source-ipaddr><sip-mask>|an
y}{<destination-ipaddr><dip-mask>|any}[dscp<0-63>][fragment][cos<0-7>][<vlan-id>[<vla
n-mask>]][<source-mac><smac-mask>|any][<dest-mac><dmac-mask>|any]
ParameterDescription
ParameterDescription
<1-16>Globalrulenumber.
permitIftheconditionmatches,accessispermitted.
denyIftheconditionmatches,accessisdenied.
<1-28>
Bindstheglobalruletoaport.Differentdeviceshavedifferent
portnumberranges.Inthesyntax,the5250-28TCdeviceisused
asanexample.
any(rst)Bindstheglobalruletoallports.
<ip-protocol>
ThisruleisonlyvalidformessageswiththespeciedIPprotocol
eld.Ignorethisruleforothermessages.TherangeofIPprotocol
eldvalueis0to255.
4-249
SJ-20131111172707-003|2013-11-27(R1.0)ZTEProprietaryandCondential