Qtech QSW-8200-52T-AC [13/114] Access list mac ip extended

Qtech QSW-8200-52T-AC [13/114] Access list mac ip extended
User Manual
Chapter 1. Commands for ACL 13
www.qtech.ru
Functions: Define an extended numeric MAC ACL rule, no access-list <num>
command deletes an extended numeric MAC access-list rule.
Parameters: <num> is the access-list No. which is a decimal’s No. from 1100-1199;
deny if rules are matching, deny access; permit if rules are matching, permit access;
<any-source-mac> any source address; <any-destination-mac> any destination
address; <host_smac>, <smac> source MAC address; <smac-mask> mask (reverse
mask) of source MAC address; <host_dmac> , <dmac> destination MAC address;
<dmac-mask> mask (reverse mask) of destination MAC address; untagged-eth2 format
of untagged ethernet II packet; tagged-eth2 format of tagged ethernet II packet;
untagged-802-3 format of untagged ethernet 802.3 packet; tagged-802-3 format of
tagged ethernet 802.3 packet. Offset(x) the offset from the packet head, the range is
(12-79), the windows must start from the back of source MAC, and the windows cannot
superpose each other, and that is to say: Offset(x1) must be longer than Offset(x)
lenx; Length(x) length is 1-4, and Offset(x)Length(x) should not be longer than
80currently should not be longer than 64; Value(x) hex expression, Value range:
when Length(x) =1, it is 0-ff, when Length(x) =2, it is 0-ffff , when Length(x) =3, it is0-
ffffff, when Length(x) =4, it is 0-ffffffff ;
For Offset(x), different types of data frames are with different value ranges:
for untagged-eth2 type frame: <1275>
for untagged-802.2 type frame: <2075>
for untagged-eth2 type frame: <1279>
for untagged-eth2 type frame: <1215> <2479>
Command Mode: Global mode
Default Configuration: No access-list configured
Usage Guide: When the user assign specific <num> for the first time, ACL of the serial
number is created, then the lists are added into this ACL.
Examples: Permit tagged-eth2 with any source MAC addresses and any destination
MAC addresses and the packets whose 17th and 18th byte is 0x08, 0x0 to pass.
Switch(config)#access-list 1100 permit any-source-mac any-destination-mac tagged-
eth2 16 2 0800
1.7 access-list(mac-ip extended)
Command:
access-list<num>{deny|permit}{any-source-mac| {host-source-
mac<host_smac>}|{<smac><smac-mask>}} {any-destination-mac|{host-destination-
mac <host_dmac>}|{<dmac><dmac-mask>}}icmp {{<source><source-wildcard>}|any-
source|{host-source<source-host-ip>}} {{<destination><destination-wildcard>}|any-
destination| {host-destination<destination-host-ip>}}[<icmp-type> [<icmp-code>]]
[precedence <precedence>] [tos <tos>][time-range<time-range-name>]
access-list<num>{deny|permit}{any-source-mac| {host-source-
mac<host_smac>}|{<smac><smac-mask>}} {any-destination-mac|{host-destination-

Содержание

Похожие устройства