The acl-id command binds an ACL to a service scheme.
The undo acl-id command unbinds the ACL from the service scheme.
By default, no ACL is bound to a service scheme.
acl-id [ ipv6 ] acl-number
undo acl-id { [ ipv6 ] acl-number | all }
S6720-HI, S5732-H, S6730-H, S6730S-H, S6730-S, S6730S-S, S5731-H, S5731S-H, S5731-S, S5731S-S, S5730-HI, S2720-EI, S5720-LI, S5720S-LI, S5720-SI, S5720S-SI, S5720I-SI, S5730-SI, S5730S-EI, S6720-LI, S6720S-LI, S6720-SI, and S6720S-SI do not support the ipv6 parameter.
Parameter | Description | Value |
---|---|---|
acl-number |
Specifies the number of an ACL bound to a service scheme. |
The value is an integer that ranges from 3000 to 3999. |
ipv6 |
Indicates that the ACL bound to a service scheme is an IPv6 ACL. If this parameter is not specified, the ACL bound to a service scheme is an IPv4 ACL. |
- |
all |
Deletes the numbers of all ACLs bound to a service scheme. |
- |
Usage Scenario
After creating a service scheme using the service-scheme command, you can run the acl-id command to bind an ACL to the service scheme. The user assigned with the service scheme will have the ACL rules.
Prerequisites
An IPv4 ACL must have been created using the acl or acl name command.
An IPv6 ACL has been created using the acl ipv6 or acl ipv6 name command.
Precautions
If the ACL authorized to users who go online through S5720-HI, S5731-H, S5731S-H, S5731-S, S5731S-S, S5732-H, S6730-H, S6730S-H, S6730-S, S6730S-S, S5730-HI, and S6720-HI is not a user-defined one, the attribute of the source IP address in the ACL rule does not take effect. In all other cases, the IP address in the ACL rule is replaced with the user's IP address. The IP address in the ACL rule will be replaced with the user's IP address.