Access Control List ACL
There are five types of ACLs on Huawei devices. Taking CX600 into consideration there are:
- Basic ACL (number ranges from 2000 to 2999) classifies packets based on a source address
- Advanced ACL (number ranges from 3000 to 3999) source address, destination address, source port number, destination port number, and protocol type
- Interface-based ACL (number ranges from 1000 to 1999) classifies packets based on the interface from which the packets are received
- Ethernet Frame Header ACL (number ranges from 4000 to 4099) classifies packets based on source and destination MAC addresses
- User ACL (number ranges from 6000 to 9999) classifies packets based on user groups.
The rules order depends on rule ID and rule matching order. There are two matching orders:
- Configuration order – ACL rules are matched based on their configuration order. Rules IDs can be configured by user or generated by system automatically according to ACL step. By default the system generates 5 as the first rule ID. So the next rule ID will be 10, 15 and so on. Anytime you can configure rule ID manually, for example rule 1 and this rule will be placed before 5. You do not have to delete the whole ACL. Each time you can delete a specific rule without deleting the whole ACL.
- Automatic order – the most precise rule is taking as the first. This is implemented through the comparison of wildcard masks. The system assigns rule IDs automatically.