Interface-based ACL rules are defined based on packets' inbound interfaces to filter packets.
The system view is displayed.
The interface ACL view is displayed.
A rule is configured for the interface ACL.
Adding new rules to an ACL will not affect the existing rules.
When an existing rule is edited and the edited contents conflict with the original contents, the edited contents take effect.
When you configure an interface ACL:
If an interface is specified by configuring interface, the system filters only packets received by this specified interface.
If all interfaces are specified by configuring any, the system does not check packets' inbound interfaces, and considers that all packets have matched the rule and directly takes an action (deny or permit) on the packets.
If a validity period is specified by configuring time-range, the time range name specified by time-name must already exist. Otherwise, the rule configuration fails.
The description for an ACL rule is configured.
The configuration is committed.