EasyManua.ls Logo

Zte ZXR10 8900 Series - Configuring ACLs

Zte ZXR10 8900 Series
186 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Chapter9ACLConguration
calport,VLANorSmartgroupvirtualinterface)supportstwoACL
processingmodesandcanprocesspacketsinthesetwomodes.
ConfiguringACLs
ACLcongurationincludes:
DeneanACLrule
Congureatimerange
ApplytheACLtoaport
DefiningACLs
Thefollowingissuesaretobetakenintoaccountwhendening
ACLrules.
Whenapacketmeetsmultiplerules,rstrulewillbematched.
Rulesequenceisveryimportant.Generally,rulesinasmall
rangeareputinthefrontandrulesinalargerangeareputin
theback.
Consideringnetworksecurity,systemwilladdanimplicitdeny
ruletotheendofeachACLautomaticallyfordenyingallthe
packets.Apermitruleforallowingallpacketsshouldbede-
nedattheendofeachACL.
DefiningStandardACL
TocongurestandardACL,performthefollowingsteps.
Step
CommandFunction
1
ZXR10(config)#aclstandard{number<acl-number
>|name<acl-name>|alias<alias-name>}[match-
order{auto|config}]
ThisentersstandardACL
congurationmode
2
ZXR10(config-std-acl)#rule<rule-no>{permit|deny
}{<source>[<source-wildcard>]|any}[time-range
<timerange-name>]
Thisdenesrules
3
ZXR10(config-std-acl)#move<rule-no>after
<rule-no>
Thismovesarule
4
ZXR10(config-std-acl)#attachtime-range<Time
rangename>to<ruleid>
Thisbindsatimerangetoa
rule
ExampleThisexampledescribeshowtodeneastandardACLwhichal-
lowsaccessofmessagesfromnetwork192.168.1.0/24butdenies
messagesfromsourceIPaddress192.168.1.100.
ZXR10(config)#aclbasicnumber10
ZXR10(config-std-acl)#rule1deny192.168.1.1000.0.0.0
CondentialandProprietaryInformationofZTECORPORATION79

Table of Contents

Other manuals for Zte ZXR10 8900 Series

Related product manuals