Zte ZXR10 3800-8 Installation instructions

ZXR10
Router/EthernetSwitch
CommandManual(SecurityVolume)
Version4.8.22
ZTECORPORATION
ZTEPlaza,KejiRoadSouth,
Hi-TechIndustrialPark,
NanshanDistrict,Shenzhen,
P .R.China
518057
Tel:(86)75526771900
Fax:(86)75526770801
URL:http://ensupport.zte.com.cn
E-mail:[email protected]

LEGALINFORMATION
Copyright©2006ZTECORPORATION.
Thecontentsofthisdocumentareprotectedbycopyrightlawsandinternationaltreaties.Anyreproductionordistributionof
thisdocumentoranyportionofthisdocument,inanyformbyanymeans,withoutthepriorwrittenconsentofZTECORPO-
RATIONisprohibited.Additionally,thecontentsofthisdocumentareprotectedbycontractualcondentialityobligations.
Allcompany,brandandproductnamesaretradeorservicemarks,orregisteredtradeorservicemarks,ofZTECORPORATION
oroftheirrespectiveowners.
Thisdocumentisprovided“asis” ,andallexpress,implied,orstatutorywarranties,representationsorconditionsaredis-
claimed,includingwithoutlimitationanyimpliedwarrantyofmerchantability,tnessforaparticularpurpose,titleornon-in-
fringement.ZTECORPORATIONanditslicensorsshallnotbeliablefordamagesresultingfromtheuseoforrelianceonthe
informationcontainedherein.
ZTECORPORATIONoritslicensorsmayhavecurrentorpendingintellectualpropertyrightsorapplicationscoveringthesubject
matterofthisdocument.ExceptasexpresslyprovidedinanywrittenlicensebetweenZTECORPORATIONanditslicensee,
theuserofthisdocumentshallnotacquireanylicensetothesubjectmatterherein.
ZTECORPORATIONreservestherighttoupgradeormaketechnicalchangetothisproductwithoutfurthernotice.
UsersmayvisitZTEtechnicalsupportwebsitehttp://ensupport.zte.com.cntoinquirerelatedinformation.
TheultimaterighttointerpretthisproductresidesinZTECORPORATION.
RevisionHistory
RevisionNo.RevisionDateRevisionReason
R1.0Dec.28,2008FirstEdition
SerialNumber:sjzl20086542

AboutThisManual..............................................i
CommandIntroduction.....................................1
ManualUseGuide...........................................................1
DescriptionofMan-MachineCommands.............................1
AuxiliaryFunction...........................................................2
CommandMode.............................................................3
ACLConguration..............................................7
aclstandard...................................................................8
aclextended..................................................................8
aclhybrid......................................................................9
acllink..........................................................................9
acluser-dened............................................................10
acl-log.........................................................................11
acl-stat........................................................................11
attach..........................................................................12
clear-acl-statistics.........................................................13
description...................................................................13
deny(StandardFormat).................................................14
deny(ExtendedFormat).................................................14
deny(IPv6StandardFormat)..........................................16
deny(IPv6ExtendedFormat)..........................................16
ipaccess-group.............................................................17
ipaccess-groupIPv6.................................................18
ipaccess-group-senior...................................................18
ipaccess-list.................................................................19
ipv6aclextended..........................................................20
ipv6aclstandard...........................................................20
move...........................................................................21
name...........................................................................21
permit(StandardFormat)...............................................22
permit(ExtendedFormat)...............................................23
permit(IPv6StandardFormat)........................................24
permit(IPv6ExtendedFormat).......................................24
rule(BasicACL)............................................................25
rule(ExtendedACL).......................................................26
rule(Layer2ACL).........................................................28
rule(HybridACL)..........................................................29
rule(User-denedACL)..................................................31

rule(IPv6StandardFormat)...........................................32
rule(IPv6ExtendedFormat)...........................................33
showaccess-listalias.....................................................34
showaccess-listbound...................................................34
showaccess-listbrief.....................................................35
showaccess-listcong...................................................35
showaccess-listseniorbound.........................................35
showaccess-listseniorvlan-bound..................................36
showaccess-listused.....................................................36
showacl.......................................................................36
showacl-statistics.........................................................37
NetworkSecurityConguration......................39
arpprotect...................................................................39
arpsource-ltered.........................................................40
arpto-static..................................................................40
ipverify.......................................................................41
showarparp-to-static....................................................41
showradius..................................................................42
showssh......................................................................42
sshserverauthenticationispgroup...................................43
sshserverauthenticationtype.........................................43
sshserverauthenticationmode.......................................44
sshserverenable..........................................................44
sshservergenerate-key.................................................45
sshserveronly..............................................................45
sshserverversion.........................................................45
urpflog........................................................................46
VirusScanningConguration..........................47
virus-scanlimit-number.................................................47
virus-scanprotectreactive-port-mode..............................47
virus-scanprotectshutdown-port....................................48
virus-scanset...............................................................48
InternetKeySwitchingProtocol
Commands......................................................51
authentication...............................................................51
clearisakmppolicy........................................................52
clearisakmpsa.............................................................53
debugcryptoisakmp......................................................53
encryption....................................................................54

group...........................................................................54
hash............................................................................55
isakmpenable...............................................................56
isakmpexchange-mode..................................................56
isakmpidentity.............................................................57
isakmpkey...................................................................58
isakmppolicy................................................................58
lifetime........................................................................60
showisakmpexchange-mode..........................................61
showisakmpidentity.....................................................61
showisakmpkey...........................................................61
showisakmppolicy........................................................62
showisakmpsa.............................................................63
IPSecIPv4NetworkSafecommands...............65
clearcryptoipsecsa......................................................65
clearcryptomap...........................................................66
cryptodynamic-map......................................................67
cryptoipseccommit.......................................................68
cryptoipsecpmtudiscover.............................................68
cryptoipsecsaglobal-lifetime.........................................69
cryptoipsectransform-set..............................................70
cryptoipsectransform-setencapsulation-mode.................70
cryptomap...................................................................71
cryptomap...................................................................72
cryptomapisakmpdynamic...........................................73
debugcryptoipsec........................................................74
enableipsec.................................................................74
matchaddress..............................................................74
setpeer.......................................................................75
setpfs.........................................................................76
setpfslevel...................................................................76
setsalifetime...............................................................77
setsession-key.............................................................78
settransform-set...........................................................79
showcryptodynamic-map..............................................79
showcryptoipsectransform-set......................................80
showcryptoipsecsaglobal-lifetime.................................81
showcryptoipsecsa......................................................81
IPSecIPv6NetworkSecurityCommands........83
ipsec............................................................................83

sadadd........................................................................84
sadclear......................................................................85
saddelall......................................................................86
saddelete....................................................................87
sadush......................................................................87
showsad......................................................................88
showspd......................................................................89
spdadd........................................................................90
spddelete....................................................................91
spdush......................................................................93
SYNFLOODProtection.....................................95
tcpsynood-protectenable.............................................95
tcpsynood-protectdefence...........................................95
tcpsynood-protectdisable............................................96
tcpsynood-protectmax-connect....................................97
tcpsynood-protectone-minute......................................97
showtcpsynood-protectall...........................................98
showtcpsynood-protectcong.....................................99
showtcpsynood-protectstatistics................................100
BFDConguration.........................................103
bfd-version.................................................................103
bfdinterval.................................................................103
showbfdneighborsbrief..............................................104
showbfdneighborsdetail.............................................104
showbfdneighborsldp-lsp...........................................104
showbfdneighborsrsvp-lsp..........................................104
L2TPConguration........................................105
clearvpdntunnel........................................................105
force-local-chap..........................................................106
initial-toip..................................................................106
l2tphidden.................................................................106
l2tpsequence.............................................................107
l2tptunnelauthentication.............................................107
l2tptunnelhello..........................................................107
l2tptunnelpassword....................................................107
l2tptunnelreceive-windows..........................................108
l2tptunnelretransmitretries........................................108
l2tptunnelretransmittimeout.......................................108
l2tptunneltimeout......................................................108
lcprenegotiation.........................................................109

localname..................................................................109
mplsl2transportpwe3extension...................................109
mplsl2transportpwe3extensionreectorrepeater..........110
new-random...............................................................110
proxy-authentication....................................................111
service-type................................................................111
showvpdnsession.......................................................111
showvpdntunnel........................................................111
source-ip....................................................................112
user-vpdn-group.........................................................112
virtual-template..........................................................113
vlan-import................................................................113
vpdndefaultvpdn-group..............................................114
vpdnenable................................................................114
vpdnfast-switch..........................................................114
vpdnradius-authenticationvpdn-group..........................115
vpdn-group................................................................115
Tacacs+Conguration...................................117
aaaaccountingcommands............................................117
aaaauthentication.......................................................118
aaaauthorization........................................................118
aaagroup-servertacacs+.............................................119
server........................................................................120
tacacs-client...............................................................120
tacacsdisable.............................................................121
tacacsenable..............................................................121
tacacs-serverhost.......................................................121
tacacs-serverkey........................................................122
tacacs-serverpacket....................................................122
tacacs-servertimeout..................................................123
RADIUSConguration...................................125
accounting-group........................................................125
accounting-groupalgorithm..........................................126
accounting-groupalias.................................................126
accounting-groupcalling-station-format.........................127
accounting-groupdeadtime...........................................127
accounting-groupipmng..............................................128
accounting-groupipvrf................................................128
accounting-groupinterim-packet-quota..........................129
accounting-grouplocal-buffer........................................129

accounting-groupmax-retries.......................................130
accounting-groupnas-ip-address...................................130
accounting-groupserver...............................................131
accounting-grouptimeout.............................................131
accounting-groupuser-name-format..............................132
accounting-groupvendor..............................................132
authentication-group....................................................133
authentication-groupalgorithm.....................................133
authentication-groupalias............................................134
authentication-groupcalling-station-format.....................134
authentication-groupdeadtime......................................135
authentication-groupipmng.........................................135
authentication-groupipvrf...........................................136
authentication-groupmax-retries..................................136
authentication-groupnas-ip-address..............................137
authentication-groupserver..........................................137
authentication-grouptimeout........................................138
authentication-groupuser-name-format.........................138
authentication-groupvendor.........................................139
radiusauto-change......................................................139
showcongurationradiusall.........................................140
AAAConguration.........................................141
aaaaccounting............................................................141
aaaauthentication.......................................................142
aaaauthorization........................................................142
aaacontrol.................................................................143
aaadefault-isp............................................................143
aaafullaccount............................................................144
aaagroupname...........................................................144
aaakeepalive..............................................................145
aaamultiple-hosts.......................................................145
aaaprotocol...............................................................146
aaaradius-server........................................................146
clearaaa....................................................................147
clearclient..................................................................147
clearlocaluser.............................................................148
createaaa..................................................................148
createlocaluser...........................................................149
localuseraccounting....................................................149
localusermac..............................................................150

localuserport..............................................................150
localuservlan..............................................................151
nas............................................................................151
showaaa....................................................................151
showclient.................................................................154
showlocaluser............................................................155
Dot1xConguration......................................159
dot1xmax-requests.....................................................159
dot1xquiet-period.......................................................159
dot1xre-authentication................................................160
dot1xserver-timeout...................................................160
dot1xsupplicant-timeout..............................................161
dot1xtx-period...........................................................161
showdot1x.................................................................162
CPUProtectionConguration........................163
debugport-upsend......................................................163
port-upsend................................................................164


AboutThisManual
PurposeThismanualprovidesproceduresandguidelinesthatsupportthe
operationofZXR10routerandEthernetswitch.
Intended
Audience
Thismanualisintendedforengineersandtechnicianswhoperform
operationactivitiesonZXR10routerandEthernetswitch.
WhatIsinThis
Manual
Thismanualcontainsthefollowingchapters:
ChapterSummary
Chapter1,Command
Introduction
Thischapterdescribestheusemethod
ofthecommandmanual,command
description,formatconvention,auxiliary
functionandmode.
Chapter2,ACL
Conguration
ThischapterdescribestheACL
congurationandcommandsofthe
Ethernetswitch.
Chapter3,Network
SecurityConguration
ThischapterdescribestheURPFSSH
congurationandviewcommands.
Chapter4,Virus
ScanningConguration
Thischapterdescribestheconguration
andviewcommandsofthevirusscanning.
Chapter5,Internet
KeySwitchingProtocol
Commands
ThischapterdescribesInternetkey
switchingprotocolcommandsandview
commands.ItisappliedtoZXR10GAR.
Chapter6,IPSecIPv4
NetworkSafecommands
ThischapterdescribesIPSecIPv4
congurationcommandsandview
commands.ItisappliedtoZXR10GAR.
Chapter7,IPSec
IPv6NetworkSecurity
Commands
ThischapterdescribesIPSecconguration
andviewcommands.Currently,onlyIPV6
appliesIPSecprotectionfunction,itmeans
thatprovideIPSecprotectionbasedon
transformmodeforroutingprotocolssuch
asOSPFv3BGP4+RIPng.
Chapter8,SYNFLOOD
Protection
Thischapterdescribessynoodprotection
associatedconguration.
Chapter9,BFD
Conguration
ThischapterdescribesBFDconguration
anddebugcommand.
Chapter10,L2TP
Conguration
ThischapterdescribesL2TPconguration
anddebugcommand.
Chapter11,Tacacs+
Conguration
Thischapterdescribestheconguration
commandsofTacacs+T erminalaccess
controlprotocol.
Chapter12,RADIUS
Conguration
Thischapterdescribestheconguration
andviewcommandsoftheRADIUS.
CondentialandProprietaryInformationofZTECORPORATIONi

ZXR10CommandManual(SecurityVolume)
ChapterSummary
Chapter13,AAA
Conguration
Thischapterdescribestheconguration
andviewcommandsofAAA.
Chapter14,Dot1x
Conguration
Thischapterdescribestheconguration
andviewcommandsofDot1x.
Chapter15,CPU
ProtectionConguration
Thischapterdescribestheconguration
andviewcommandsofCPUprotection.
Related
Documentation
Thefollowingdocumentationisrelatedtothismanual:
�ZXR10Router/EthernetSwitchCommandManual(Command
IndexVolume)
�ZXR10Router/EthernetSwitchCommandManual(Ethernet
SwitchVolume)
�ZXR10Router/EthernetSwitchCommandManual(BasicCon-
gurationVolumeI)
�ZXR10Router/EthernetSwitchCommandManual(BasicCon-
gurationVolumeII)
�ZXR10Router/EthernetSwitchCommandManual(BasicCon-
gurationVolumeIII)
�ZXR10Router/EthernetSwitchCommandManual(RemoteAc-
cessVolume)
�ZXR10Router/EthernetSwitchCommandManual(IPv4Rout-
ingVolumeI)
�ZXR10Router/EthernetSwitchCommandManual(IPv4Rout-
ingVolumeII)
�ZXR10Router/EthernetSwitchCommandManual(MPLSVol-
ume)
�ZXR10Router/EthernetSwitchCommandManual(QoSVol-
ume)
�ZXR10Router/EthernetSwitchCommandManual(Network
ManagementVolume)
�ZXR10Router/EthernetSwitchCommandManual(Multicast
Volume)
�ZXR10Router/EthernetSwitchCommandManual(IPv6Vol-
ume)
�ZXR10Router/EthernetSwitchCommandManual(Voiceand
VideoServiceVolume)
iiCondentialandProprietaryInformationofZTECORPORATION

Chapter1
CommandIntroduction
TableofContents
ManualUseGuide...............................................................1
DescriptionofMan-MachineCommands.................................1
AuxiliaryFunction...............................................................2
CommandMode.................................................................3
ManualUseGuide
Thecommandsinothervolumesareclassiedbyfunctionalmod-
ules,andeachfunctionalmodulecorrespondstoachapterand
thecommandsinthechapterareorganizedintheformoflevel2
directoryandintheorderofa–z.
Tosearchacommand,doasfollows:
1.FindthedesiredcommandbyreferringtoZXR10Router/Eth-
ernetSwitchCommandManual—CommandIndex.
2.Findcommanddetailsbythevolume,chapter/sectionandpage
oftheobtainedcommand.
DescriptionofMan-Machine
Commands
EachMMLcommandisdescribedbythefollowingitems:
�Function
Itdescribesthefunctionimplementedbythiscommand.
�CommandMode
Itdescribesthemodeinwhichthiscommandcanbeexecuted.
�Format
Itdescribesthecompleteformatofthiscommand,including
thenoformatifpossible.
�ParameterDescription
Itdescribesparametersinthiscommandintheformandpre-
scribestherangeanddefaultvalue.Ifdifferentproductshave
CondentialandProprietaryInformationofZTECORPORATION1

ZXR10CommandManual(SecurityVolume)
differentparameterrangesordefaultvalues,anadditional
formisusedfordescription.
�Default
Thedefaultvalueisavailableinthecasethatthiscommandis
notset.Thedefaultparametervalueisnotdescribedherefor
valueselection.
Additionaldescriptionshallbegivenifdifferentproductshave
differentdefaultvalues.
�Instructions
Firstdescribestheplatformversioninformationaboutthis
command.Forexample,“TheplatformversionX.X.XXorlater
supportsthiscommand”indicatesthiscommandisprovided
fromthebeginningoftheplatformversionX.X.XX.Thiscom-
mandisprovidedfromtheplatformversion2.6bydefault.
Seconddescribestheusemethodandprecautionsofthiscom-
mand.
�Example
Itdescribestheuseofthiscommandinanexample.
�RelatedCommands
Liststhecommand(s)relatedtothiscommand.
�HistoryCommand
Itdescribeshistoryversioninformationrelatedtothiscom-
mandifacommandischangedafterversionupgrade.
Donotdescribethehistorycommandifthisentrydoesnotexist.
AuxiliaryFunction
TheauxiliaryfunctionforZXR10devicesisasfollows.
1.Inanycommandmode,enteraquestionmark(?)afterthe
DOSpromptofthesystem,alistofavailablecommandsinthe
commandmodewillbedisplayed.Withthecontext-sensitive
helpfunction,thekeywordsandparameterlistsofanycom-
mandscanbeobtained.
i.Inanycommandmode,enteraquestionmark"?"afterthe
DOSpromptofthesystem,andalistofallcommandsin
themodeandthebriefdescriptionofthecommandswill
bedisplayed.
ii.Inputthequestionmarkbehindacharacterorcharacter
stringtoviewthelistofcommandsorkeywordsbeginning
withthischaracterorcharacterstring.Notethatthereis
nospacebetweenthecharacter(string)andthequestion
mark.
iii.PressTABbehindthecharacterstring.Ifthecommandor
keywordbeginningwiththischaracterstringisunique,it
shallbecompletedwithaspaceattheend.Notethatthere
isnospacebetweenthecharacterstringandtheTAB.
2CondentialandProprietaryInformationofZTECORPORATION

Chapter1CommandIntroduction
iv.Inputaquestionmarkafteracommand,akeywordora
parameter ,thenextkeywordorparametertobeinputwill
belisted,andalsoabriefexplanationwillbegiven.Note
thataspacemustbeenteredbeforethequestionmark.
2.Ifincorrectcommand,keywordorparameterisinput,theerror
isolationisofferedwith^intheuserinterfaceafteryoupress
ENTER.The^isbelowtherstcharacteroftheinputincorrect
command,keywordorparameter .
3.ZXR10router/Ethernetswitchallowsthecommandorkey-
wordtobeabbreviatedintoacharacterorcharacterstringthat
uniquelyidentiesthiscommandorkeyword.Forexample,the
showcommandcanbeabbreviatedtoshorsho.
4.Theuserinterfacesupportsthefunctionofrecordinginput
commands.Amaximumoftenhistorycommandscanbe
recorded.Thefunctionisveryusefulinre-invocationofalong
orcomplicatedcommandoringress.
Tore-invokeacommandfromtherecordbuffer ,conductone
ofthefollowingoperations,asshownbelow.
CommandFunction
PressCTRL-Porthe
uparrowkey
Re-invokesthelatestcommandinthe
recordbuffer .Repeatthesekeysto
invokeoldcommandsforwards.
PressCTRL-Northe
downarrowkey
Rollsthecommandsdownward.Whenthe
lastcommandlineisreached,onemore
operationwillrollthecommandsfromthe
beggingofthebuffercyclically.
Inanymode,executetheshowhistorycommandtolistthe
latestcommandsinputinthismode.
CommandMode
Thecommandmodesinthismanualareshownbelow.
ModePromptAdmis-
sion
Mode
Entry
Command
Functions
Exec
mode
ZXR10>entersdirectly
afterlogging
thesystem
Viewssimple
information
Privi-
leged
mode
ZXR10#Exec
mode
enableCongures
system
parameters
Global
cong-
uration
mode
ZXR10(config)#Privi-
leged
mode
configure
terminal
Congures
globalservice
parameters
CondentialandProprietaryInformationofZTECORPORATION3

ZXR10CommandManual(SecurityVolume)
ModePromptAdmis-
sion
Mode
Entry
Command
Functions
Inter-
face
cong-
uration
mode
ZXR10(config-
if)#Global
cong-
uration
mode
interfaceCongures
port
parameters
andselects
aporttype
dependingon
thekeyword
Subin-
terface
mode
ZXR10(config-
subif)#Global
cong-
uration
mode
interfaceCongures
subinterface
parameters
ofthe
NPCI/NPCT
VLAN
data-
base
cong-
uration
mode
ZXR10(vlan-
db)#Privi-
leged
mode
vlandatab
ase
Createsor
deletesVLANs
inbatches
VLAN
cong-
uration
mode
ZXR10(config-
vlan)#Global
cong-
uration
mode
vlanCongures
VLAN
parameters
MSTP
cong-
uration
mode
ZXR10(config-
mstp)#Global
cong-
uration
mode
spanning-t
reemstconf
iguration
Congures
MSTP
parameters
Basic
ACL
cong-
uration
mode
ZXR10(config-
basic-acl)#Global
cong-
uration
mode
aclbasicDenesbasic
ACLrule
Ex-
tended
ACL
cong-
uration
mode
ZXR10(config-
ext-acl)#Global
cong-
uration
mode
aclextendDenes
extendedACL
rule
Line
cong-
uration
mode
ZXR10(config-
line)#Global
cong-
uration
mode
lineconsole
0
line<1~64
>(GAR)
Congures
parameters
relatedto
serialport
andtelnet
connection
Layer
2ACL
cong-
uration
mode
ZXR10(config-
link-acl)#Global
cong-
uration
mode
acllinkDeneslayer
2ACLrule
4CondentialandProprietaryInformationofZTECORPORATION

Chapter1CommandIntroduction
ModePromptAdmis-
sion
Mode
Entry
Command
Functions
Hybrid
ACL
cong-
uration
mode
ZXR10(config-
hybd-acl)#Global
cong-
uration
mode
aclhybridDeneshybrid
ACLrule
Router
stand-
ardACL
mode
ZXR10(config-
std-nacl)#Global
cong-
uration
mode
ipaccess-listDenesrouter
standardACL
rule
Router
ex-
tended
ACL
mode
ZXR10(config-
ext-nacl)#Global
cong-
uration
mode
ipaccess-listDenesrouter
extendedACL
rule
routerripCongures
RIP
parameters
routerospfCongures
OSPF
parameters
routerisisCongures
IS-IS
parameters
routerbgpCongures
BGP
parameters
router
pimsm
Congures
PIM-SM
parameters
ipv6router
rip
Congures
RIPng
parameters.
Route
cong-
uration
mode
ZXR10(config-
router)#Global
cong-
uration
mode
ipv6router
ospf
Congures
OSPFv3
parameters
VRF
cong-
uration
mode
ZXR10(config-
vrf)#Global
cong-
uration
mode
ipvrfCongures
VRF
parameters
VFIcon-
gu-
ration
mode
ZXR10(config-
vfi)#Global
cong-
uration
mode
vfiCongures
VPLSrelated
parameters
CondentialandProprietaryInformationofZTECORPORATION5

ZXR10CommandManual(SecurityVolume)
ModePromptAdmis-
sion
Mode
Entry
Command
Functions
Route
cong-
uration
mode
(RIP)
address-fam
ilyipv4vrf
Congures
RIPVRF
parameters
IPv4ad-
dress
family
cong-
uration
mode
ZXR10(config-
router-af)#
Route
cong-
uration
mode
(BGP)
address-fam
ilyvpnv4
address-fam
ilyipv4vrf
Congures
BGPVPN
andVRF
parameters
Route
cong-
uration
mode
(BGP4+)
address-fam
ilyipv6
Congures
BGP4+
unicast
addressfamily
IPv6
unicast
address
family
cong-
uration
mode
ZXR10(config-
router-af)#
Route
cong-
uration
mode
(IS-
ISv6)
address-fam
ilyipv6
Congures
IS-ISv6
addressfamily
Route
map
cong-
uration
mode
ZXR10(config-
route-map)#Global
cong-
uration
mode
route-mapCongures
routemap
matchingitem
andoperation
Channe-
lization
cong-
uration
mode
ZXR10(config-
control)#Global
cong-
uration
mode
controlCongures
channelization
force1,ce3
andcpos3
Dial
peer
cong-
uration
mode
ZXR10(config-
voip100)#Global
cong-
uration
mode
dial-peer
voice
Congures
business
relatedto
integrated
service
Voice
port
cong-
uration
mode
ZXR10(config-
voice-port)#Global
cong-
uration
mode
voice-portCongures
voiceservice
IPSec
cong-
uration
mode
ZXR10(config-
ipsec)#Global
cong-
uration
mode
ipsecCongures
IPv6IPSec
protection
Diagno-
sismode
ZXR10(diag)#Privi-
leged
mode
diagnoseTestsCPU
andmemory
usage
6CondentialandProprietaryInformationofZTECORPORATION

Chapter2
ACLConfiguration
TableofContents
aclstandard.......................................................................8
aclextended......................................................................8
aclhybrid..........................................................................9
acllink..............................................................................9
acluser-dened................................................................10
acl-log.............................................................................11
acl-stat............................................................................11
attach..............................................................................12
clear-acl-statistics.............................................................13
description.......................................................................13
deny(StandardFormat).....................................................14
deny(ExtendedFormat).....................................................14
deny(IPv6StandardFormat)..............................................16
deny(IPv6ExtendedFormat)..............................................16
ipaccess-group.................................................................17
ipaccess-groupIPv6.....................................................18
ipaccess-group-senior.......................................................18
ipaccess-list.....................................................................19
ipv6aclextended..............................................................20
ipv6aclstandard...............................................................20
move...............................................................................21
name...............................................................................21
permit(StandardFormat)...................................................22
permit(ExtendedFormat)...................................................23
permit(IPv6StandardFormat)............................................24
permit(IPv6ExtendedFormat)...........................................24
rule(BasicACL)................................................................25
rule(ExtendedACL)...........................................................26
rule(Layer2ACL).............................................................28
rule(HybridACL)..............................................................29
rule(User-denedACL)......................................................31
rule(IPv6StandardFormat)...............................................32
rule(IPv6ExtendedFormat)...............................................33
showaccess-listalias.........................................................34
showaccess-listbound.......................................................34
showaccess-listbrief.........................................................35
showaccess-listcong.......................................................35
showaccess-listseniorbound.............................................35
showaccess-listseniorvlan-bound......................................36
showaccess-listused.........................................................36
showacl...........................................................................36
showacl-statistics.............................................................37
CondentialandProprietaryInformationofZTECORPORATION7

ZXR10CommandManual(SecurityVolume)
aclstandard
PurposeUsethiscommandtoenterstandardACLcongurationmode,
DeletestandardACLconguredwithnoformofthiscommand.
CommandModesGlobalconguration
Syntaxaclstandard{number<acl-number>|name<acl-name>|
alias<acl-alias>}
noaclstandard{number<acl-number>|name<acl-name>|
alias<acl-alias>}
Syntax
Descriptionnumber<acl-numb
er>
StandardACLnumber ,range:1~99or
1000~1499
name<acl-name>StandardACLname,notmorethan31
characters
alias<acl-alias>ACLalias,notmorethan31characters
InstructionsThealiascanbeconguredonlyfornumberACL.Thealiasmust
beconguredbeforeitisusedwiththenamecommand.
ExampleThisexampledescribeshowtoenterstandardACLconguration
mode.
ZXR10(config)#aclstandardnumber1
ZXR10(config-std-acl)#exit
ZXR10(config)#aclstandardnameacl1
ZXR10(config-std-acl)#
Related
Commands
showacl
aclextended
PurposeUsethiscommandtoenterextendedACLcongurationmode.
DeletetheconguredextendedACLwithnoformofthiscom-
mand.
CommandModesGlobalconguration
Syntaxaclextended{number<acl-number>|name<acl-name>|
alias<acl-alias>}
noaclextended{number<acl-number>|name<acl-name>|
alias<acl-alias>}
Syntax
Descriptionnumber<acl-numb
er>
ExtendedACLnumber ,range:100~199or
1500~1999
name<acl-name>StandardACLname,notmorethan31
characters
alias<acl-alias>ACLalias,notmorethan31characters
8CondentialandProprietaryInformationofZTECORPORATION
Other manuals for ZXR10 3800-8
15
Table of contents
Other Zte Network Router manuals