HP 6125G HP 6125G & 6125G/XG Blade Switches ACL and QoS Configuration - Page 15

Configuring an Ethernet frame header ACL, Copying an ACL

Page 15 highlights

Configuring an Ethernet frame header ACL Ethernet frame header ACLs, also called "Layer 2 ACLs," match packets based on Layer 2 protocol header fields, such as source MAC address, destination MAC address, 802.1p priority (VLAN priority), and link layer protocol type. To configure an Ethernet frame header ACL: Step 1. Enter system view. Command system-view 2. Create an Ethernet frame header ACL and enter its view. acl number acl-number [ name acl-name ] [ match-order { auto | config } ] 3. Configure a description for the Ethernet frame header ACL. 4. Set the rule numbering step. description text step step-value rule [ rule-id ] { deny | permit } [ cos vlan-pri | counting | dest-mac dest-addr dest-mask | { lsap 5. Create or edit a lsap-type lsap-type-mask | rule. type protocol-type protocol-type-mask } | source-mac sour-addr source-mask | time-range time-range-name ] * 6. Add or edit a rule comment. rule rule-id comment text 7. Add or edit a rule range remark. 8. Enable counting ACL rule matches performed in hardware. rule [ rule-id ] remark text hardware-count enable Remarks N/A By default, no ACL exists. Ethernet frame header ACLs are numbered in the range of 4000 to 4999. You can use the acl name acl-name command to enter the view of a named Ethernet frame header ACL. Optional. By default, an Ethernet frame header ACL has no ACL description. Optional. The default setting is 5. By default, an Ethernet frame header ACL does not contain any rule. The lsap keyword is not supported if the ACL is for QoS traffic classification. Optional. By default, no rule comments are configured. Optional. By default, no rule range remarks are configured. Optional. Disabled by default. When the ACL is referenced by a QoS policy, this command does not take effect. Copying an ACL You can create an ACL by copying an existing ACL (source ACL). The new ACL (destination ACL) has the same properties and content as the source ACL, but not the same ACL number and name. 9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84

9
Configuring an Ethernet frame header ACL
Ethernet frame header ACLs, also called "Layer 2 ACLs," match packets based on Layer 2 protocol
header fields, such as source MAC address, destination MAC address, 802.1p priority (VLAN priority),
and link layer protocol type.
To configure an Ethernet frame header ACL:
Step
Command
Remarks
1.
Enter system
view.
system-view
N/A
2.
Create an
Ethernet frame
header ACL
and enter its
view.
acl number
acl-number
[
name
acl-name
]
[
match-order
{
auto
|
config
} ]
By default, no ACL exists.
Ethernet frame header ACLs are numbered in the
range of 4000 to 4999.
You can use the
acl
name
acl-name
command to enter
the view of a named Ethernet frame header ACL.
3.
Configure a
description for
the Ethernet
frame header
ACL.
description
text
Optional.
By default, an Ethernet frame header ACL has no ACL
description.
4.
Set the rule
numbering
step.
step
step-value
Optional.
The default setting is 5.
5.
Create or edit a
rule.
rule
[
rule-id
] {
deny
|
permit
} [
cos
vlan-pri
|
counting
|
dest-mac
dest-addr
dest-mask
| {
lsap
lsap-type
lsap-type-mask
|
type
protocol-type
protocol-type-mask
} |
source-mac
sour-addr
source-mask
|
time-range
time-range-name
] *
By default
,
an Ethernet frame header ACL does not
contain any rule.
The
lsap
keyword is not supported if the ACL is for QoS
traffic classification.
6.
Add or edit a
rule comment.
rule
rule-id
comment
text
Optional.
By default, no rule comments are configured.
7.
Add or edit a
rule range
remark.
rule
[
rule-id
]
remark
text
Optional.
By default, no rule range remarks are configured.
8.
Enable
counting ACL
rule matches
performed in
hardware.
hardware-count enable
Optional.
Disabled by default.
When the ACL is referenced by a QoS policy, this
command does not take effect.
Copying an ACL
You can create an ACL by copying an existing ACL (source ACL). The new ACL (destination ACL) has the
same properties and content as the source ACL, but not the same ACL number and name.