Qtech QSW-3200-28T [59/136] Define acl

Qtech QSW-3200-28T [59/136] Define acl
+7(495) 797-3311www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
48
Use time-range command to enter time-range configuration mode. In this mode, you can
configure time range.
Configure it in global configuration mode.
Command:
time-range time-range-name
There are two kinds of configuration: configure absolute time range and periodic time range.
Configuring absolute is in the form of year, month, date, hour and minute. Configuring periodic
time range is in the form of day of week, hour and minute.
Create absolute time range
Use following command to configure it.
Configure it in time-range configuration mode.
Configure absolute time range:
absolute [ start time date ] [ end time date ]
Delete absolute time range:
no absolute [ start time date ] [ end time date ]
If the start time is not configured, there is no restriction to the start time.; if endtime is not
configured, the end time can be the max time of system. The end time must be larger than
start time.
Absolute time range determines a large effective time and restricts the effective time range of
periodic time. It can configure 12 absolute time range.
Create periodic time range
Use following command to configure periodic time range.
Configure it in time-range configuration mode.
Command:
periodic days-of-the-week hh:mm:ss to [ day-of-the-week ] hh:mm:ss
no periodic days-of-the-week hh:mm:ss to [ day-of-the-week ] hh:mm:ss
The effective time range of periodic time is a week. It can configure at most 32 periodic time
range.
7.2.3 Define ACL
Switch supports many ACL. Followings are how to define it:
Define standard ACL
Switch can defaine at most 99 standard ACL with the number ID (the number is in the range of
1 to 99), at most 1000 standard ACL with the name ID and totally 3000 sub-rules. It can define
128 sub-rules for an ACL (this rule can suit both ACL with name ID and number ID). Standard
ACL only classifies data packet according to the source IP information of IP head of data
packet and analyse the matching data packet. The construction of IP head refers to RFC791.
(1) Define standard ACL based on number ID
Standard ACL based on number ID is using number to be ID of standard ACL. Use following
command to define standard ACL based on number ID.
Configure it in global configuration mode.
Command:
access-list access-list-number { deny | permit } { source-addr source-wildcard | any } [
fragments ] [ time-range time-range-name ]
Define the matching order of ACL:
access-list access-list-number match-order { config | auto }
Delete all the subitems or one subitem in one ACL with number ID or name ID or all ACLs.

Содержание

Похожие устройства

Скачать