NOTE
If the value of
vlan
vlan-id
is specified, it indicates that VLAN-based traffic mirroring is
configured and traffic that matches an ACL rule is filtered on all interfaces on the VLAN.
If the value of
vlan
vlan-id
is not specified, it indicates that the statistics on the traffic that
matches an ACL rule are collected on all interfaces of the device.
A Layer 2 ACL and a Layer 3 ACL can be set in the
traffic-mirror
command simultaneously.
The Layer 3 ACL and its rules can be configured only after the Layer 2 ACL and its rules are
configured. The Layer 2 ACL number ranges from 4000 to 4999 and the Layer 3 ACL number
ranges from 2000 to 2999 and 3000 to 3999. To configure both Layer 2 ACLs and Layer 3
ACLs on an inbound interface of a switch, run the following command:
traffic-mirror
[
vlan
vlan-id
]
inbound
acl
{
l2-acl
|
name
acl-name
} [
rule
rule-id
]
acl
{
bas-acl
|
adv-acl
|
name
acl-name
} [
rule
rule-id
]
to observe-port
o-index
l
Configure traffic mirroring on an interface.
1.
Run:
system-view
The system view is displayed.
2.
Run:
interface
interface-type
interface-number
or
interface eth-trunk
trunk-id
The interface view or the Eth-Trunk interface view is displayed.
3.
Run:
traffic-mirror
inbound
{
acl
{ [
ipv6
] {
bas-acl
|
adv-acl
|
name
acl-
name
} |
l2-acl
|
user-acl
} } [
rule
rule-id
]
to observe-port
o-index
The incoming packets matching an ACL rule are mirrored on an interface.
NOTE
A Layer 2 ACL and a Layer 3 ACL can be set in the
traffic-mirror
command simultaneously.
The Layer 3 ACL and its rules can be configured only after the Layer 2 ACL and its rules are
configured. The Layer 2 ACL number ranges from 4000 to 4999 and the Layer 3 ACL number
ranges from 2000 to 2999 and 3000 to 3999. To configure both Layer 2 ACLs and Layer 3
ACLs on an inbound interface of a switch, run the following command:
traffic-mirror
inbound
acl
{
l2-acl
|
name
acl-name
} [
rule
rule-id
]
acl
{
bas-acl
|
adv-
acl
|
name
acl-name
} [
rule
rule-id
]
to observe-port
o-index
----End
1.5.7 Redirecting the Traffic That Matches an ACL Rule
Context
By configuring the redirection action, the S3700 redirects the packets matching traffic
classification rules to the CPU, the specified interface, or the specified next hop address.
Procedure
l
Configuring traffic redirection globally
1.
Run:
system-view
The system view is displayed.
S3700HI Ethernet Switches
Configuration Guide - QoS
1 Class-based QoS Configuration
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
36