Chapter9ACLConguration
ZXR10(config-ext-acl)#rule4deny8anyany
DefiningLayer2ACL
TocongureLayer2ACL,performthefollowingsteps.
Step
CommandFunction
1
ZXR10(config)#acllink{number<acl-number>|name
<acl-name>|alias<alias-name>}[match-order
{auto|config}]
ThisentersLayer2ACL
congurationmode
2
ZXR10(config-link-acl)#rule<rule-no>{permi
t|deny}<protocol-number>[cos<cos-vlaue>|
incos<cos-vlaue>|dinvlan<vlan-id>|doutervlan
<vlan-id>][ingress{[<source-vlanid>][<source-
mac><source-mac-wildcard>|any]}][egress{<de
st-mac><dest-mac-wildcard>|any}][time-range
<timerange-name>]
Thisconguresrulesinan
ACL
3
ZXR10(config-link-acl)#move<rule-no>after
<rule-no>
Thismovesarule
4
ZXR10(config-link-acl)#attachtime-range<Time
rangename>to<ruleid>
Thisbindsatimerangetoa
rule
ExampleThisexampledescribeshowtodeneaL2ACLwhichallowsac-
cessofIPpacketswithsourceMACaddress00d0.d0c0.5741and
802.1pcode5.
ZXR10(config)#acllinknumber200
ZXR10(config-link-acl)#rule1permitipcos5
ingress1000d0.d0c0.57410000.0000.0000
ZXR10(config-link-acl)#rule2deny8847
DefiningHybridACL
TocongurehybridACL,performthefollowingsteps.
Step
CommandFunction
1
ZXR10(config)#aclhybrid{number<acl-number>|n
ame<acl-name>|alias<alias-name>}
ThisentershybridACL
congurationmode
2
ZXR10(config-hybd-acl)#rule<rule-no>{permit
|deny}<protocol-numberl>{{<source-ip><sour
ce-ip-wildcard>}|any}[eq<port-number>]{{<d
estination-ip><dest-ip-wildcard>}|any}[eq
<port-number>]{<ethernet-protocol-number>|any
|arp|ip}[cos|incos|dinvlan|doutervlan|
egress|ingress|time-range]
ThisdenesruleinanACL
3
ZXR10(config-hybd-acl)#move<rule-no>after
<rule-no>
Thismovesarule
4
ZXR10(config-hybd-acl)#attachtime-range<Time
rangename>to<ruleid>
Thisbindsatimerangetoa
rule
CondentialandProprietaryInformationofZTECORPORATION81