Switch 7700 Command reference Guide, v2.0

Table Of Contents
ACL Configuration Command List 277
dest-addr dest-wildcard | any: dest-addr dest-wildcard is the destination
IP address and destination address wildcard, expressed in dotted decimal notation.
any represents any destination address.
source-port operator port1 [ port2 ]: This parameter is to define the source
TCP or UDP port number. Here,
operator represents port operation character,
including eq (equal to), gt (greater than), lt (less than), neq (not equal to), and
range (in certain range). Note: This parameter is available only when
protocol
parameter takes TCP or UDP.
port1 [ port2 ]: TCP or UDP port number of
packets, expressed with characters or numbers. The numbers are in the range of 0
to 65535 and refer to mnemonic symbol table for character values.
destination-port operator port1 [ port2 ]: This parameter is to define the
destination TCP or UDP port number. The meaning of
operator port1 [port2] is
same as upper parameter.
icmp-type icmp-type icmp-code: Used when protocol is specified as icmp.
icmp-type icmp-code specifies an ICMP packet. icmp-type specifies the ICMP
packet type with a number in the range of 0 to 255 or characters.
icmp-code,
ranging from 0 to 255, is used for icmp when the ICMP packet type is not
specified with characters.
established: Used when protocol is tcp to indicate that the rule takes effect on
the first SYN packet to establish TCP connection.
precedence precedence: Specifies IP precedence with a number in the range of
0 to 7 or a name.
dscp dscp: Classifies the data packets with a number in the range of 0 to 63 or a
name.
tos tos: Classifies the data packets with a number in the range of 0 to 15 or a
name.
fragment: Indicates that the rule takes effect on fragmented packets only and will
be ignored for other packets.
The parameter of interface ACL:
interface { interface-name | interface-type interface-num | any }:
Specifies L3 interface name.
interface-name is the interface name, expressed as
interface-type plus interface-num to represent an interface. In a switch, the
L3 interface can only be a VLAN interface, that is,
interface-type can be
specified as VLAN Interface only.
any represents all the L3 interfaces.
The parameter of link ACL
protocol-type: Protocol carried by an Ethernet frame, which can be ip, arp, or
rarp.
format-type: encapsulation format, which can be 802.3/802.2, 802.3, ether_ii,
snap.
ingress { [ source-vlan-id ] [ source-mac-addr ] | any }: Source
information of a data packet.
[ source-vlan-id ] specifies the source VLAN of