ACL Ethernet Filter configuration

Command: /cfg/acl/acl <1-4096>/ethernet
[Filtering Ethernet

Menu]

 

smac

- Set

to filteron source MAC

dmac

- Set

to filter

on destination MAC

vlan

- Set

to filter

on VLAN ID
etype

- Set

to filter

on ethernet type
pri- Set to filteron priority

reset

- Reset all fields

cur

- Display current parameters

 

 

 

 

This menu allows you to define Ethernet matching criteria for an ACL. The following table describes the Ethernet Filter Configuration Menu options.

Table 174 Ethernet Filter Configuration Menu options

Command

Description

 

 

smac <MAC address>Defines the source MAC address for this ACL. For example:

 

00:60:cf:40:56:00

 

 

dmac <MAC address>

Defines the destination MAC address for this ACL. For example:

 

00:60:cf:40:56:00

 

 

vlan <1-4095> <VLAN mask (0xfff)>Defines a VLAN number and mask for this ACL.

 

 

etype ARPIPIPv6MPLSRARPany0xXXXXDefines the Ethernet type for this ACL.

 

 

pri <0-7>Defines the Ethernet priority value for the ACL.

 

 

reset

Resets Ethernet parameters for the ACL to their default values.

 

 

cur

Displays the current Ethernet parameters for the ACL.

 

 

ACL IP Version 4 Filter configuration

Command: /cfg/acl/acl <1-4096>/ipv4
[Filtering IPv4

Menu]

sip

-

Set to filter on source IP address

dip

-

Set to filter on destination IP address
proto

-

Set to filter on protocol
tos

-

Set to filter on TOS

reset

-

Reset all fields

cur

-

Display current parameters

 

 

 

This menu allows you to define IPv4 matching criteria for an ACL. The following table describes the IP version 4 Filter Configuration Menu options.

Table 175 IPv4 Filter Configuration Menu options

Command

Description

 

 

 

sip <IP address>

Defines a source IP address for the ACL. If defined, traffic with this source IP address will

 

match this ACL. Specify an IP address in dotted decimal notation. For example, 100.10.1.1

 

 

dip <IP address>

Defines a destination IP address for the ACL. If defined, traffic with this destination IP address

 

will match this ACL. For example, 100.10.1.2

 

 

proto <0-255>

Defines an IP protocol for the ACL. If defined, traffic from the specified protocol matches this

 

filter. Specify the protocol number. Listed below are some of the well-known protocols.

 

NumberName

 

1

icmp

 

2

igmp

 

6

tcp

 

17

udp

 

89

ospf

 

112

vrrp

 

 

tos <0-255>

Defines a Type of Service value for the ACL. For more information on ToS, see RFC 1340

 

and 1349.

 

 

 

 

Configuration Menu 151