Chapter4ServiceConguration
ParameterDescription
permitIftheconditionmatches,accessispermitted.
denyIftheconditionmatches,accessisdenied.
<1-28>
Bindstheglobalruletoaport.Differentdeviceshavedifferent
portnumberranges.Inthesyntax,the5250-28TCdeviceisused
asanexample.
any(rst)Bindstheglobalruletoallports.
arp
ThisruleonlymatchesARPpacket.Thenon-ARPpacketignores
thisrule.
<sender-ipaddr>
SendernetworkandhostaddressofARPpacket.Itisa32-bitIP
addressexpressedindotteddecimalnotation.
<sip-mask>
Sourcemaskusedforsources.Itisa32-bitIPaddressexpressed
indotteddecimalnotation.
any(second)
Theanykeywordisusedastheabbreviationofthedestination
0.0.0.0andthedestinationmask0.0.0.0.
<target-ipaddr>
DestinationnetworkandhostaddressofARPpacket.Itisa32-bit
IPaddressexpressedindotteddecimalnotation.
<tip-mask>
Destinationmask.Itisa32-bitIPaddressexpressedindotted
decimalnotation.
any(third)
Theanykeywordisusedastheabbreviationofthedestination
0.0.0.0andthedestinationmask0.0.0.0.
cos<0-7>
Thisruleisonlyvalidforthecos-speciedmessage.Ignorethis
ruleforothermessages.Therangeofcosis0to7.
<vlan-id>
ThisruleisonlyvalidformessageswiththespeciedVLANID.
Ignorethisruleforothermessages.TheruleofVLANIDis1
to4094.
<vlan-mask>
ThisruleisonlyvalidformessageswiththespeciedVLANID.
Ignorethisruleforothermessages.TheruleofVLANIDis1
to4094.
<source-mac>SourceMACaddressofthetransmittedpacket.
<smac-mask>SourceMACmask.
any(fourth)
TheanykeywordisusedastheabbreviationofsourceMAC
address00.00.00.00.00.00andmask00.00.00.00.00.00.
<dest-mac>DestinationMACaddressofthetransmittedpacket.
<dmac-mask>DestinationMACaddressofthetransmittedpacket.
any(fth)
TheanykeywordisusedastheabbreviationofdestinationMAC
address00.00.00.00.00.00andmask00.00.00.00.00.00.
4-257
SJ-20131111172707-003|2013-11-27(R1.0)ZTEProprietaryandCondential