Qtech QSW-2910-09T-POE-AC/DC Руководство пользователя онлайн [93/212] 481587

Qtech QSW-2910-09T-POE-AC/DC Руководство пользователя онлайн [93/212] 481587
+7(495) 797-3311 www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
93
200 to 299), at most 1000 layer 2 ACL with the name ID and totally 3000 sub-rules. It can
define 128 sub-rules for an ACL (this rule can suit both ACL with name ID and number ID).
Layer 2 ACL only classifies data packet according to the source MAC address, source VLAN
ID, layer protocol type, layer packet received and retransmission interface and destination
MAC address of layer 2 frame head of data packet and analyze the matching data packet.
1. Define layer 2 ACL based on number ID
Layer 2 ACL based on number ID is using number to be ID of layer 2 ACL. Use following
command to define layer 2 ACL based on number ID.
Configure it in global configuration mode.
(1) Define layer 2 ACL based on number ID
access-list access-list-number3 { permit | deny } [ protocol ] [ cos vlan-pri ] ingress
{ { [ source-vlan-id ] [ source-mac-addr source-mac-wildcard ] [ interface interface-num ] } |
any } egress { { [ dest-mac-addr dest-mac-wildcard ] [ interface interface-num | cpu ] } | any }
[ time-range time-range-name ]
(2) Define the matching order of ACL:
access-list access-list-number match-order { config | auto }
(3) Delete all the subitems or one subitem in one ACL with number ID or name ID or all
ACLs.
no access-list { all | { access-list-number | name access-list-name } [ subitem ] }
Use access-list command repeatedly to define more rules for the same ACL.
The number ID of layer 2 ACL is in the range of 200 to 299.
Interface parameter in above command specifies layer 2 interface, such as Ethernet interface.
Concrete parameter meaning refers to corresponded command line.
2. Define layer 2 ACL with name ID.
Layer 2 ACL with name ID is using name ID to identify layer 2 ACL.
Instruction:
Defining layer 2 ACL with name ID should enter specified configuration mode: use access-list
link in global configuration mode which can specify matching order of ACL. Use exit command
to be back from this mode.
Use following commands to define layer 2 ACL with name ID. Configure it in corresponded
mode.
(1) Enter layer 2 ACL with name ID configuration mode(global configuration mode)

Содержание

Скачать