HP 6125XLG R2306-HP 6125XLG Blade Switch ACL and QoS Command Reference - Page 19

packet-filter default deny, Examples, Related commands, Syntax, Default, Views, Predefined user roles

Page 19 highlights

• 3000 to 3999 for IPv4 advanced ACLs s if the ipv6 keyword is not specified and for IPv6 advanced ACLs if the ipv6 keyword is specified. • 4000 to 4999 for Ethernet frame header ACLs. This entry is not displayed if the ipv6 keyword is specified. name acl-name: Specifies an ACL by its name. The acl-name argument is a case-insensitive string of 1 to 63 characters. It must start with an English letter. For a basic ACL or advanced ACL, if you do not specify the ipv6 keyword, this option specifies the name of an IPv4 basic ACL or advanced ACL. If you specify the ipv6 keyword, this option specifies the name of an IPv6 basic ACL or advanced ACL. inbound: Filters incoming packets. outbound: Filters outgoing packets. hardware-count: Enables counting ACL rule matches performed in hardware. This keyword enables match counting for all rules in an ACL, and the counting keyword in the rule command enables match counting specific to rules. If the hardware-count keyword is not specified, rule matches for the ACL are not counted. Examples # Apply IPv4 basic ACL 2001 to filter incoming traffic on FortyGigE 1/1/1, and enable counting ACL rule matches performed in hardware. system-view [Sysname] interface FortyGigE 1/1/1 [Sysname-FortyGigE1/1/1] packet-filter 2001 inbound hardware-count Related commands • display packet-filter • display packet-filter statistics • display packet-filter verbose packet-filter default deny Use packet-filter default deny to set the packet filtering default action to deny. The packet filter denies packets that do not match any ACL rule. Use undo packet-filter default deny to restore the default. Syntax packet-filter default deny undo packet-filter default deny Default The packet filter permits packets that do not match any ACL rule. Views System view Predefined user roles network-admin 14

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114

14
3000 to 3999 for IPv4 advanced ACLs s if the
ipv6
keyword is not specified and for IPv6 advanced
ACLs if the
ipv6
keyword is specified.
4000 to 4999 for Ethernet frame header ACLs. This entry is not displayed if the
ipv6
keyword is
specified.
name
acl-name
: Specifies an ACL by its name. The
acl-name
argument is a case-insensitive string of 1 to
63 characters. It must start with an English letter. For a basic ACL or advanced ACL, if you do not specify
the
ipv6
keyword, this option specifies the name of an IPv4 basic ACL or advanced ACL. If you specify
the
ipv6
keyword, this option specifies the name of an IPv6 basic ACL or advanced ACL.
inbound
: Filters incoming packets.
outbound
: Filters outgoing packets.
hardware-count
: Enables counting ACL rule matches performed in hardware. This keyword enables
match counting for all rules in an ACL, and the
counting
keyword in the
rule
command enables match
counting specific to rules. If the
hardware-count
keyword is not specified, rule matches for the ACL are
not counted.
Examples
# Apply IPv4 basic ACL 2001 to filter incoming traffic on FortyGigE 1/1/1, and enable counting ACL
rule matches performed in hardware.
<Sysname> system-view
[Sysname] interface FortyGigE 1/1/1
[Sysname-FortyGigE1/1/1] packet-filter 2001 inbound hardware-count
Related commands
display
packet-filter
display
packet-filter
statistics
display
packet-filter
verbose
packet-filter default deny
Use
packet-filter
default
deny
to set the packet filtering default action to
deny
. The packet filter denies
packets that do not match any ACL rule.
Use
undo
packet-filter
default
deny
to restore the default.
Syntax
packet-filter
default
deny
undo
packet-filter
default
deny
Default
The packet filter permits packets that do not match any ACL rule.
Views
System view
Predefined user roles
network-admin