TP-Link TL-SG5412F TL-SG5428 V1 CLI Reference Guide - Page 153

acl rule std-acl, TP-LINKconfig# acl edit rule mac-acl, smask

Page 153 highlights

destination-mac -- The destination MAC address contained in the rule. destination-mac-mask -- The destination MAC address mask. It is required if you typed the destination MAC address. vlan-id -- The VLAN ID contained in the rule, ranging from 1 to 4094. Ethernet-type -- EtherType contained in the rule, in the format of 4-hex number. user-pri -- The user priority contained in the rule, ranging from 0 to 7. By default, it is not limited. time-segment -- The time-range for the rule to take effect. By default, it is not limited. index -- Change the index number of the entry. Command Mode Global Configuration Mode Example Edit the MAC ACL whose ID is 20, and add Rule 10 for it. In the rule, the source MAC address is 00:01:3F:48:16:23, the source MAC address mask is 11:11:11:11:11:00, VLAN ID is 2, the user priority is 5, the time-range for the rule to take effect is tSeg1, and the packets match this rule will be forwarded by the switch: TP-LINK(config)# acl edit rule mac-acl 20 10 op permit smac 00:01:3F:48:16:23 smask 11:11:11:11:11:00 vid 2 pri 5 tseg tSeg1 acl rule std-acl Description The acl rule std-acl command is used to add Standard-IP ACL rule. To delete the corresponding rule, please use no acl rule std-acl command. Standard-IP ACLs analyze and process data packets based on a series of match conditions, which can be the source IP addresses and destination IP addresses carried in the packets. Syntax acl rule std-acl {acl-id} {rule-id} [op {discard | permit}] [[sip source-ip] {smask source-ip-mask}] [[dip destination-ip] {dmask destination-ip-mask}] [tseg time-segment] no acl rule std-acl {acl-id} {rule-id} 141

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

141
destination-mac
—— The destination MAC address contained in the rule.
destination-mac-mask
—— The destination MAC address mask. It is required if
you typed the destination MAC address.
vlan-id
—— The VLAN ID contained in the rule, ranging from 1 to 4094.
Ethernet-type
—— EtherType contained in the rule, in the format of 4-hex
number.
user-pri
—— The user priority contained in the rule, ranging from 0 to 7. By
default, it is not limited.
time-segment
—— The time-range for the rule to take effect. By default, it is not
limited.
index
—— Change the index number of the entry.
Command Mode
Global Configuration Mode
Example
Edit the MAC ACL whose ID is 20, and add Rule 10 for it. In the rule, the source
MAC address is 00:01:3F:48:16:23, the source MAC address mask is
11:11:11:11:11:00, VLAN ID is 2, the user priority is 5, the time-range for the rule
to take effect is tSeg1, and the packets match this rule will be forwarded by the
switch:
TP-LINK(config)# acl edit rule mac-acl
20 10
op
permit
smac
00:01:3F:48:16:23
smask
11:11:11:11:11:00
vid
2
pri
5
tseg
tSeg1
acl rule std-acl
Description
The
acl rule std-acl
command is used to add Standard-IP ACL rule. To delete
the corresponding rule, please use
no acl rule std-acl
command. Standard-IP
ACLs analyze and process data packets based on a series of match conditions,
which can be the source IP addresses and destination IP addresses carried in
the packets.
Syntax
acl rule std-acl
{
acl-id
} {
rule-id
} [
op
{discard | permit}] [[
sip
source-ip
] {
smask
source-ip-mask
}] [[
dip
destination-ip
] {
dmask
destination-ip-mask
}] [
tseg
time-segment
]
no acl rule std-acl
{
acl-id
} {
rule-id
}