beautypg.com

Setting the packet filtering default action, Displaying and maintaining acls – H3C Technologies H3C S6300 Series Switches User Manual

Page 20

background image

10

Step Command

Remarks

3.

Specify the applicable
scope of packet filtering on

the VLAN interface.

packet-filter filter [ route | all ]

By default, the packet filtering filters
packets forwarded at Layer 3.

Setting the interval for generating and outputting packet
filtering logs

After you set the interval, the device periodically generates and outputs the packet filtering logs to the
information center, including the number of matching packets and the matched ACL rules. For more

information about information center, see Network Management and Monitoring Configuration Guide.
To set the interval for generating and outputting packet filtering logs:

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Set the interval for generating

and outputting packet filtering
logs.

acl [ ipv6 ] logging interval interval

The default setting is 0 minutes,
which mean that no packet filtering

logs are generated.

Setting the packet filtering default action

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Set the packet filtering default
action to deny.

packet-filter default deny

By default, the packet filter permits
packets that do not match any ACL

rule to pass.

Displaying and maintaining ACLs

Execute display commands in any view and reset commands in user view.

Task Command

Display ACL configuration and match statistics.

display acl [ ipv6 ] { acl-number | all | name
acl-name }

Display whether an ACL has been successfully applied
to an interface for packet filtering.

display packet-filter { interface [ interface-type
interface-number ] [ inbound | outbound ] | interface

vlan-interface vlan-interface-number [ inbound |
outbound ] [ slot slot-number ] }

Display match statistics for packet filtering ACLs.

display packet-filter statistics interface interface-type
interface-number { inbound | outbound } [ [ ipv6 ]

{ acl-number | name acl-name } ] [ brief ]