10
Step Command
Remarks
4.
Create or edit a rule.
rule
[
rule-id
]
{
deny
|
permit
}
[ {
l2
rule-string
rule-mask
offset
}&<1-8> ] [
counting
|
time-range time-range-name
] *
By default, no user-defined ACL
rules exist.
5.
(Optional.) Add or edit a rule
comment.
rule
rule-id comment
text
By default, no rule comment is
configured.
Copying an ACL
You can create an ACL by copying an existing ACL (source ACL). The new ACL (destination ACL)
has the same properties and content as the source ACL, but uses a different number or name than
the source ACL.
To successfully copy an ACL, make sure:
•
The destination ACL number is from the same type as the source ACL number.
•
The source ACL already exists, but the destination ACL does not.
To copy an ACL:
Step Command
1.
Enter system view.
system-view
2.
Copy an existing ACL to create a new ACL.
acl
[
ipv6
|
mac
|
user-defined
]
copy
{
source-acl-number
|
name
source-acl-name
}
to
{
dest-acl-number
|
name
dest-acl-name
}
Configuring packet filtering with ACLs
This section describes procedures for using an ACL to filter packets. For example, you can apply an
ACL to an interface to filter incoming or outgoing packets.
NOTE:
•
The packet filtering feature is available on Layer 2 Ethernet interfaces, Layer 2 aggregate
interfaces, Layer 3 Ethernet interfaces, Layer 3 Ethernet subinterfaces, Layer 3 aggregate
interfaces, VLAN interfaces, and VSI interfaces.
•
For VSI interfaces, the packet filtering feature is available in Release 2510P01 and later.
•
The term "interface" in this section collectively refers to these types of interfaces. You can use the
port link-mode
command to configure an Ethernet port as a Layer 2 or Layer 3 interface (see
Layer 2—LAN Switching Configuration Guide
).
Applying an ACL to an interface for packet filtering
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface interface-type
interface-number
N/A
Summary of Contents for FlexFabric 5940 Series
Page 23: ...17 Figure 3 QoS processing flow ...
Page 84: ...78 Figure 26 MPLS label structure ...
Page 91: ...85 Switch burst mode enable ...