Qtech QSW-3300-28F-AC-AC Руководство администратора онлайн [624/693] 481604

Qtech QSW-3300-28F-AC-AC Руководство администратора онлайн [624/693] 481604
MAC Access Control List Commands
Software User Manual
CLI Command Reference
Page 641
If a sequence number is not specified for the rule, a sequence number that is 10 greater than the last sequence
number in ACL is used and this rule is placed in the end of the list. If this is the first ACL rule in the given ACL,
a sequence number of 10 is assigned. If the calculated sequence number exceeds the maximum sequence
number value, the ACL rule creation fails. A rule cannot be created that duplicates an already existing one and
a rule cannot be configured with a sequence number that is already used for another rule.
For example, if user adds new ACL rule to ACL without specifying a sequence number, it is placed at the bottom
of the list. By changing the sequence number, the user can move the ACL rule to a different position in the ACL.
The Ethertype may be specified as either a keyword or a four-digit hexadecimal value from 0x0600-0xFFFF. The
currently supported
ethertypekey values are: appletalk, arp, ibmsna, ipv4, ipv6, ipx, mplsmcast, mplsucast,
netbios, novell, pppoe, rarp. Each of these translates into its equivalent Ethertype value(s).
The
vlan and cos parameters refer to the VLAN identifier and 802.1p user priority fields, respectively, of the
VLAN tag. For packets containing a double VLAN tag, this is the first (or outer) tag.
The
time-range parameter allows imposing time limitation on the MAC ACL rule as defined by the parameter
time-range-name
. If a time range with the specified name does not exist and the MAC ACL containing this ACL
rule is applied to an interface or bound to a VLAN, then the ACL rule is applied immediately. If a time range with
specified name exists and the MAC ACL containing this ACL rule is applied to an interface or bound to a VLAN,
then the ACL rule is applied when the time-range with specified name becomes active. The ACL rule is removed
when the time-range with specified name becomes inactive. For information about configuring time ranges, see
“Time Range Commands for Time-Based ACLs” on page 671.
The
assign-queue parameter allows specification of a particular hardware queue for handling traffic that
matches this rule. The allowed queue-id value is 0-(n-1), where n is the number of user configurable queues
available for the hardware platform. The
assign-queue parameter is valid only for a permit rule.
Table 11: Ethertype Keyword and 4-digit Hexadecimal Value
Ethertype Keyword Corresponding Value
appletalk 0x809B
arp 0x0806
ibmsna 0x80D5
ipv4 0x0800
ipv6 0x86DD
ipx 0x8037
mplsmcast 0x8848
mplsucast 0x8847
netbios 0x8191
novell 0x8137, 0x8138
pppoe 0x8863, 0x8864
rarp 0x8035

Содержание

Скачать