
12
name acl-name: Specifies an ACL by its name. The acl-name argument is a case-insensitive string of 1 to
63 characters. It must start with an English letter.
slot slot-number: Specifies an IRF member device. The slot-number argument represents the ID of the IRF
member device. If you do not specify an IRF member device, this command displays ACL application
details for packet filtering on the master.
Usage guidelines
When none of acl-number and name acl-name is specified, this command displays application details of
all ACLs for packet filtering.
• If the ipv6 keyword is not specified, all ACLs refer to all IPv4 basic, IPv4 advanced, and Ethernet
frame header ACLs.
• If the ipv6 keyword is specified, all ACLs refer to all IPv6 basic and IPv6 advanced ACLs.
Examples
# Display application details of all ACLs (IPv4 basic, IPv4 advanced, and Ethernet frame header ACLs)
for incoming packet filtering on FortyGigE 1/1/1.
<Sysname> display packet-filter verbose interface fortygige 1/1/1 inbound
Interface: FortyGigE1/1/1
In-bound policy:
ACL 2001, Hardware-count
rule 0 permit
rule 5 permit source 1.1.1.1 0
ACL6 2000, Hardware-count
rule 0 permit
ACL 4000, Hardware-count
IPv4 default action: Deny
IPv6 default action: Deny
MAC default action: Deny
Table 5 Command output
Field Descri
tion
Interface Interface to which the ACL applies.
In-bound policy ACL used for filtering incoming traffic.
Out-bound policy ACL used for filtering outgoing traffic.
ACL 2001 IPv4 basic ACL 2001 has been successfully applied.
Hardware-count Successfully enables counting ACL rule matches.
IPv4 default action
Packet filter default action for packets that do not match any IPv4
ACLs. This field is displayed only when the default action is
deny.
IPv6 default action
Packet filter default action for packets that do not match any IPv6
ACLs. This field is displayed only when the default action is
deny.
Kommentare zu diesen Handbüchern