S3526的ACL设置初探

来源:互联网 发布:剑三成男捏脸详细数据 编辑:程序博客网 时间:2024/06/08 11:06

rule-map
flow-action
acl {acl_name} {rule_name} {action_name}
acl {acl_name} {rule_name} {action_name} time-range {time-range_name} on/off
rule-map l2 {rule_name} ingress [Ethernet {slot/port}]/[any] egress [Ethernet {slot/port}]/[any]
rule-map l2 {rule_name} vlan {vlan_id} ingress [H.H.H]/[any] egress [H.H.H]/[any]
rule-map l3 {rule_name} {source_ip} {source_mask} {dest_ip} {dest_mask}
rule-map l3 {rule_name} {source_ip} {source_mask} eq {protocol} {dest_ip} {dest_mask} eq {protocol}
rule-map l3 {rule_name} {source_ip} {source_mask} range {protocol_from} {protocol_to} {dest_ip} {dest_mask} range {protocol_from} {protocol_to}
rule-map l3 {rule_name} protocol-type icmp/tcp/udp {source_ip} {source_mask} {dest_ip} {dest_mask}
flow-action {action_name} car {car_name} cos {cos_value}
flow-action {action_name} cos {cos_value}
flow-action {action_name} deny
flow-action {action_name} gather
flow-action {action_name} monitor-port
gather 1 (a) [I, Ipr, Ip, Tn, Tn.pr, Tn.p] ~ round (sb/sth); ~ sb/sth round (sb/sth) come or bring sb/sth together in one place 聚集; 集合; 召集; 搜集
deny 1 [Tn, Tf, Tnt, Tg] say that (sth) is not true 否认, 否定(某事)

原创粉丝点击