Qtech QSW-2900-24T4-AC [129/209] Define layer 2 acl

8-127
b) Define extended ACL with name ID
Defining standard ACL with name ID should enter specified configuration mode: use access-list extended in
global configuration mode which can specify matching order of ACL. Use exit command to be back from this mode.
Configure it in corresponded mode. Enter extended ACL with name ID (global configuration mode).
access-list extended name [ match-order { config | auto } ]
Define extended ACL (extended ACL with name ID configuration mode)
{ permit | deny } [ protocol ] [ established ] { source-addr source-wildcard | any } [ port
[ portmask ] ] { dest-addr dest-wildcard | any } [ port [ portmask ] ] [ icmp-type [ icmp-code ] ]
[ fragments ] [ time-range time-range-name ]
Delete all the subitems or one subitem in one ACL with number ID or name ID or all ACLs.(global
configuration mode)
no access-list { all | { access-list-number | name access-list-name } [ subitem ] }
Use { permit | deny } command repeatedly to define more rules for the same ACL. Specifying matching order
cannot be modified.
Caution: parameter port means TCP or UDP interface numberused by all kinds of superior levels. For some
common interface number, use corresponded mnemonic symbol to replace the real number, such as using bgp to
instead of the TCP interface number 179 of BGP protocol. Details refer to corresponded command line.
8.3.5 Define layer 2 ACL
Switch can define at most 100 layer 2 ACL with the number ID (the number is in the range of 200 to 299), at
most 1000 layer 2 ACL with the name ID and totally 3000 sub-rules. It can define 128 sub-rules for an ACL (this rule
can suit both ACL with name ID and number ID). Layer 2 ACL only classifies data packet according to the source
MAC address, source VLAN ID, layer protocol type, layer packet received and retransmission interface and
destination MAC address of layer 2 frame head of data packet and analyze the matching data packet.
a) Define layer 2 ACL based on number ID
Layer 2 ACL based on number ID is using number to be ID of layer 2 ACL. Use following command to define
layer 2 ACL based on number ID.
Configure it in global configuration mode.
access-list access-list-number3 { permit | deny } [ protocol ] ingress { { [ source-vlan-id ] [ interface
interface-num ] } | any } [ time-range time-range-name ]
Define the matching order of ACL:
access-list access-list-number match-order { config | auto }
Delete all the subitems or one subitem in one ACL with number ID or name ID or all ACLs.
no access-list { all | { access-list-number | name access-list-name } [ subitem ] }
Use access-list command repeatedly to define more rules for the same ACL.
The number ID of layer 2 ACL is in the range of 200 to 299.
Interface parameter in above command specifies layer 2 interface, such as Ethernet interface. Concrete
parameter meaning refers to corresponded command line.
b) Define layer 2 ACL with name ID.
Defining layer 2 ACL with name ID should enter specified configuration mode: use access-list link in global
configuration mode which can specify matching order of ACL. Use exit command to be back from this mode.
Enter layer 2 ACL with name ID configuration mode(global configuration mode)

Содержание

Скачать