To do…

 

Use the command…

Remarks

Enter system view

 

system-view

 

 

 

 

 

 

packet-filter vlan vlan-id

Required

Apply an ACL to a VLAN

 

For description on the acl-rule

 

inbound acl-rule

argument, refer to ACL Command.

 

 

 

 

 

 

 

Configuration example

# Apply ACL 2000 to VLAN 10 to filter the inbound packets of VLAN 10 on all the ports.

<device> system-view

[device] packet-filter vlan 10 inbound ip-group 2000

Assigning an ACL to a Port Group

Configuration prerequisites

Before applying ACL rules to a VLAN, you need to define the related ACLs. For information about defining an ACL, refer to Configuring Basic ACL, Configuring Advanced ACL, Configuring Layer 2 ACL.

Configuration procedure

Follow these steps to assign an ACL to a port group:

 

To do…

Use the command…

Remarks

 

 

Enter system view

system-view

 

 

 

 

 

 

 

Enter port group view

port-group group-id

 

 

 

 

 

 

 

Apply an ACL to the port

 

Required

 

 

packet-filter inbound acl-rule

For description on the acl-rule

 

 

group

 

argument, refer to ACL Command.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

After an ACL is assigned to a port group, it will be automatically assigned to the ports that are subsequently added to the port group.

Configuration example

# Apply ACL 2000 to port group 1 to filter the inbound packets on all the ports in the port group.

<device> system-view

[device] port-group 1

[device-port-group-1] packet-filter inbound ip-group 2000

1-10

Page 353
Image 353
3Com WX3000 operation manual Assigning an ACL to a Port Group, System-view Packet-filter vlan vlan-id, Inbound acl-rule