3com 8807 User Guide
VLAN-ACL Configuration
217
newly added one. However, if the port delete the self-defined flow template,
the system will apply QACL rules in the VLAN to the new port automatically.
the system will apply QACL rules in the VLAN to the new port automatically.
■
You will fail to change the flow template applied to a port with a VLAN-ACL
already applied to a customized flow template.
already applied to a customized flow template.
2 If both a VLAN and one of its ports have QACL rules applied, only those applied to
the port work. In this case, the VLAN-ACL takes effect only after the QACL rules
and the self-defined flow template on the port are deleted.
and the self-defined flow template on the port are deleted.
3 When the VLAN contains no ports, the system is prohibited from applying
VLAN-ACL (including adding and deleting rules).
4 Two ports differing in VLAN-ACL configuration cannot be aggregated dynamically.
5 A VLAN-ACL is prohibited from being applied to a VLAN containing intermixing
ports. Similarly, a VLAN with a VLAN-ACL applied to is prohibited from being used
for MPLS intermixing.
for MPLS intermixing.
c
CAUTION: VLAN-ACL does not take effect on the ports of the XP4 card.
VLAN-ACL Configuration
Example
Network requirements
Set the next hop IP address of all the packets forwarded by GigabitEthernet7/1/1
and GigabitEthernet7/1/2 ports from 8:00 to 18:00 every day to 3.0.0.1.
and GigabitEthernet7/1/2 ports from 8:00 to 18:00 every day to 3.0.0.1.
Network diagram
Figure 57 Network diagram for VLAN-ACL configuration
Configuration procedure
1 Define the time range.
# Define the time range from 8:00 to 18:00.
<SW8800> system-view
System View: return to User View with Ctrl+Z.
[SW8800] time-range 3Com 8:00 to 18:00 daily
2 Define traffic rules.
# Create ACL 2000 and enter the corresponding view.
[SW8800] acl number 2000
GE7/1/8
GE7/1/1
GE7/1/2
VLAN2
1.0.0.1/8
PC1
GE7/1/2
PC1
VLAN2
2.0.0.1/8
PC2
PC2
3.0.0.1/8
PC3
GE7/1/2
PC1
GE7/1/2
PC1
2.0.0.1/8
PC2
PC2
PC3
GE7/1/2
VLAN2
PC1
GE7/1/2
PC1
VLAN2
2.0.0.1/8
PC2
PC2
PC3
GE7/1/2
PC1
GE7/1/2
PC1
2.0.0.1/8
PC2
PC2
PC3
GE7/1/8
GE7/1/1
GE7/1/2
VLAN2
1.0.0.1/8
PC1
GE7/1/2
PC1
VLAN2
2.0.0.1/8
PC2
PC2
3.0.0.1/8
PC3
GE7/1/2
PC1
GE7/1/2
PC1
2.0.0.1/8
PC2
PC2
PC3
GE7/1/2
VLAN2
PC1
GE7/1/2
PC1
VLAN2
2.0.0.1/8
PC2
PC2
PC3
GE7/1/2
PC1
GE7/1/2
PC1
2.0.0.1/8
PC2
PC2
PC3