z
With the
config
match order specified for the basic ACL, you can modify any existent rule. The
unmodified part of the rule remains. With the
auto
match order specified for the basic ACL, you
rule; otherwise the system will tell you that the rule cannot be modified.
the
rule-id
argument when creating an ACL rule, the rule will be numbered
er of the rule will
umber plus one. If the current greatest rule number is 65534, however, the
rule cannot be created and you need to specify a number for the rule.
with the content of any existing rule;
il, and the system prompts that the rule already
ly created rules will be inserted in the existent ones by
the numbers of the existent rules are unaltered.
C
packets whose source IP addresses are 192.168.0.1.
<Sysname> system-view
information of ACL 2000.
Configuring Advanced ACL
ckets by their source and destination IP addresses, the protocols carried
by IP, and protocol-specific features such as TCP/UDP source and destination ports, ICMP message
Advanced ACLs support analysis and processing of three packet priority levels: type of service (ToS)
entiated services codepoint (DSCP).
ules that are more accurate, more abundant, and
more flexible
e defined for basi
Configuration prerequisites
z
as
ou need to create the corresponding time
ion ab
uration, re
ime Range
cannot modify any existent
z
If you do not specify
automatically. If the ACL has no rules, the rule is numbered 0; otherwise, the numb
be the greatest rule n
system will tell you that the
z
The content of a modified or created rule cannot be identical
otherwise the rule modification or creation will fa
exists.
z
With the
auto
match order specified, the new
depth-first principle, but
onfiguration example
# Configure ACL 2000 to deny
[Sysname] acl number 2000
[Sysname-acl-basic-2000] rule deny source 192.168.0.1 0
# Display the configuration
[Sysname-acl-basic-2000] display acl 2000
Basic ACL 2000, 1 rule
Acl's step is 1
rule 0 deny source 192.168.0.1 0
An advanced ACL can filter pa
type and message code.
An advanced ACL can be numbered from 3000 to 3999. Note that ACL 3998 and ACL 3999 cannot be
configured because they are reserved for cluster management.
priority, IP priority and differ
Using advanced ACLs, you can define classification r
than thos
c ACLs.
To configure a time range-b
ranges first. For informat
ed advanced ACL rule, y
out of time range config
fer to
Configuring T
.
z
The settings to be specified in the rule, such as source and destination IP addresses, the protocols
carried by IP, and protocol-specific features, are determined.
44-6