HP 6125G HP 6125G & 6125G/XG Blade Switches ACL and QoS Command Refere - Page 6

ACL configuration commands, acl

Page 6 highlights

ACL configuration commands acl Syntax acl number acl-number [ name acl-name ] [ match-order { auto | config } ] View undo acl { all | name acl-name | number acl-number } System view Default level 2: System level Parameters number acl-number: Specifies the number of an access control list (ACL): • 2000 to 2999 for IPv4 basic ACLs • 3000 to 3999 for IPv4 advanced ACLs • 4000 to 4999 for Ethernet frame header ACLs name acl-name: Assigns a name to the ACL for easy identification. The acl-name argument takes a case-insensitive string of 1 to 63 characters. It must start with an English letter, and to avoid confusion, cannot be all. match-order: Sets the order in which ACL rules are compared against packets: • auto-Compares ACL rules in depth-first order. The depth-first order differs with ACL categories. For more information, see ACL and QoS Configuration Guide. • config-Compares ACL rules in ascending order of rule ID. The rule with a smaller ID has higher priority. If no match order is specified, the config order applies by default. all: Deletes all IPv4 ACLs and Ethernet frame header ACLs. Description Use acl to create an IPv4 ACL or an Ethernet frame header ACL, and enter its view. If the ACL has been created, you enter its view directly. Use undo acl to delete the specified IPv4 or Ethernet frame header ACL, or all IPv4 and Ethernet frame header ACLs. By default, no ACL exists. You can assign a name to an IPv4 or Ethernet frame header ACL only when you create it. After an ACL is created with a name, you cannot rename it or remove its name. You can change match order only for ACLs that do not contain any rules. To display any ACLs you have created, use the display acl command. Examples # Create IPv4 basic ACL 2000, and enter its view. system-view 1

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104

1
ACL configuration commands
acl
Syntax
acl number
acl-number
[
name
acl-name
] [
match-order
{
auto
|
config
} ]
undo
acl
{
all
|
name
acl-name
|
number
acl-number
}
View
System view
Default level
2: System level
Parameters
number
acl-number
: Specifies the number of an access control list (ACL):
2000 to 2999 for IPv4 basic ACLs
3000 to 3999 for IPv4 advanced ACLs
4000 to 4999 for Ethernet frame header ACLs
name
acl-name
: Assigns a name to the ACL for easy identification. The
acl-name
argument takes a
case-insensitive string of 1 to 63 characters. It must start with an English letter, and to avoid confusion,
cannot be
all
.
match-order
: Sets the order in which ACL rules are compared against packets:
auto
—Compares ACL rules in depth-first order. The depth-first order differs with ACL categories. For
more information, see
ACL and QoS Configuration Guide
.
config
—Compares ACL rules in ascending order of rule ID. The rule with a smaller ID has higher
priority. If no match order is specified, the config order applies by default.
all
: Deletes all IPv4 ACLs and Ethernet frame header ACLs.
Description
Use
acl
to create an IPv4 ACL or an Ethernet frame header ACL, and enter its view. If the ACL has been
created, you enter its view directly.
Use
undo
acl
to delete the specified IPv4 or Ethernet frame header ACL, or all IPv4 and Ethernet frame
header ACLs.
By default, no ACL exists.
You can assign a name to an IPv4 or Ethernet frame header ACL only when you create it. After an ACL
is created with a name, you cannot rename it or remove its name.
You can change match order only for ACLs that do not contain any rules.
To display any ACLs you have created, use the
display acl
command.
Examples
# Create IPv4 basic ACL 2000, and enter its view.
<Sysname> system-view