Configure Bridge’s Routing Function 303

When creating an ACL based on Ethernet type code (Ethernet-II, SNAP or LSAP), you can specify aclt-numberin the range of 200 to 299. type-codeis a 16-bit hexadecimal number written with a leading “0x”, corresponding to the type-code field in the Ethernet-II or SNAP frames. type-wildcardis a 16-bit hexadecimal number written with a leading “0x” and used to specify the shielded bits.

When creating an ACL, note that:

The rules will be compared in the order in which they are configured.

If no rule is matched, Ethernet frames should still be permitted to pass.

The number of created rules cannot exceed 200.

7Apply ACLs on Ports

Perform the following configuration in interface view. a Apply ACLs based on MAC addresses on ports

Table 335 Apply ACLs based on MAC addresses on ports

Operation

Command

 

 

Apply ACLs based on MAC addresses in the

bridge-set bridge-setsource-mac

input direction of ports

acl acl-number

 

 

Remove the application of ACLs based on

undo bridge-set bridge-set

MAC addresses in the input direction of ports

source-mac acl acl -number

 

 

Apply ACLs based on MAC addresses in the

bridge-set bridge-setdest-mac acl

output direction of ports

acl-number

 

 

Remove the application of ACLs based on

undo bridge-set bridge-set

MAC addresses in the input direction of ports

dest-mac acl acl-number

 

 

By default, no ACL is applied on the port.

bApply an ACL encapsulated in the form of IEEE 802.2 on the port

Table 336 Apply an ACL encapsulated in the form of IEEE 802.2 on the port

Operation

Command

 

 

Apply an ACL encapsulated in the form of

bridge-set bridge-setinbound-lsap

IEEE 802.2 to the input side of the port

acl acl-number

 

 

Remove the application of the ACL

undo bridge-set bridge-set

encapsulated in the form of IEEE 802.2 to the

inbound-lsap acl acl-number

input side of the port

 

 

 

Apply the ACL encapsulated in the form of

bridge-set bridge-set

IEEE 802.2 to the output side of the port

outbound-lsap acl -number

 

 

Remove the application of the ACL

undo bridge-set bridge-set

encapsulated in the form of IEEE 802.2 to the

outbound-lsap acl acl-number

output side of the port

 

 

 

By default, no ACL is applied on the port.

cApply an ACL encapsulated in the form of Ethernet-II/Ethernet-SNAP on the port

Table 337 Apply an ACL encapsulated in the form of IEEE 802.2 on the port

Operation

Command

 

 

Apply an ACL encapsulated in the form of

bridge-set bridge-set

Ethernet-II or Ethernet-SNAP to the input side

inbound-type acl acl-number

of the port

 

 

 

Page 307
Image 307
3Com 10014299 manual Acl acl-number