HwAclAdvancedRuleEntry |
|
SEQUENCE |
|
|
|
|
hwAclAdvancedAclNum |
Integer32 |
|
|
hwAclAdvancedSubitem |
Unsigned32 |
|
|
hwAclAdvancedAct |
INTEGER |
|
|
hwAclAdvancedProtocol |
Integer32 |
|
|
hwAclAdvancedSrcIp |
IpAddress |
|
|
hwAclAdvancedSrcWild |
IpAddress |
|
|
hwAclAdvancedSrcOp |
INTEGER |
|
|
hwAclAdvancedSrcPort1 |
Integer32 |
|
|
hwAclAdvancedSrcPort2 |
Integer32 |
|
|
hwAclAdvancedDestIp |
IpAddress |
|
|
hwAclAdvancedDestWild |
IpAddress |
|
|
hwAclAdvancedDestOp |
INTEGER |
|
|
hwAclAdvancedDestPort1 |
Integer32 |
|
|
hwAclAdvancedDestPort2 |
Integer32 |
|
|
hwAclAdvancedPrecedence |
Integer32 |
|
|
hwAclAdvancedTos |
Integer32 |
|
|
hwAclAdvancedDscp |
Integer32 |
|
|
hwAclAdvancedEstablish |
TruthValue |
|
|
hwAclAdvancedTimeRangeIndex |
Integer32 |
|
|
hwAclAdvancedIcmpType |
Integer32 |
|
|
hwAclAdvancedIcmpCode |
Integer32 |
|
|
hwAclAdvancedFragments |
INTEGER |
|
|
hwAclAdvancedLog |
TruthValue |
|
|
hwAclAdvancedEnable |
TruthValue |
|
|
hwAclAdvancedCount |
Counter64 |
|
|
hwAclAdvancedVrfName |
OCTET STRING |
|
|
hwAclAdvancedRowStatus |
RowStatus |
|
|
hwAclAdvancedTcpSyncFlag |
Integer32 |
|
|
hwAclAdvancedDescription |
OCTET STRING |
|
|
hwAclAdvancedSrcPoolName |
OCTET STRING |
|
|
hwAclAdvancedDestPoolName |
OCTET STRING |
|
|
hwAclAdvancedProtocolNew |
Integer32 |
|
|
hwAclAdvancedVni |
Integer32 |
|
|
hwAclAdvancedIgmpType |
Integer32 |
|
|
hwAclAdvancedTtlOp |
INTEGER |
|
|
hwAclAdvancedTtlExpire |
Integer32 |
|
|
hwAclAdvancedTtlExpireEnd |
Integer32 |
|
|
hwAclAdvancedPktLenOp |
INTEGER |
|
|
hwAclAdvancedPktLenBegin |
Integer32 |
|
|
hwAclAdvancedPktLenEnd |
Integer32 |
|
HwAclUserRuleEntry |
|
SEQUENCE |
|
|
|
|
hwAclUserAclNum |
Integer32 |
|
|
hwAclUserSubitem |
Unsigned32 |
|
|
hwAclUserAct |
INTEGER |
|
|
hwAclUserProtocol |
Integer32 |
|
|
hwAclUserSrcIp |
IpAddress |
|
|
hwAclUserSrcWild |
IpAddress |
|
|
hwAclUserSrcOp |
INTEGER |
|
|
hwAclUserSrcPort1 |
Integer32 |
|
|
hwAclUserSrcPort2 |
Integer32 |
|
|
hwAclUserDestIp |
IpAddress |
|
|
hwAclUserDestWild |
IpAddress |
|
|
hwAclUserDestOp |
INTEGER |
|
|
hwAclUserDestPort1 |
Integer32 |
|
|
hwAclUserDestPort2 |
Integer32 |
|
|
hwAclUserPrecedence |
Integer32 |
|
|
hwAclUserTos |
Integer32 |
|
|
hwAclUserDscp |
Integer32 |
|
|
hwAclUserEstablish |
TruthValue |
|
|
hwAclUserTimeRangeIndex |
Integer32 |
|
|
hwAclUserIcmpType |
Integer32 |
|
|
hwAclUserIcmpCode |
Integer32 |
|
|
hwAclUserFragments |
TruthValue |
|
|
hwAclUserLog |
TruthValue |
|
|
hwAclUserEnable |
TruthValue |
|
|
hwAclUserCount |
Counter32 |
|
|
hwAclUserVrfName |
OCTET STRING |
|
|
hwAclUserSrcUserGroupName |
OCTET STRING |
|
|
hwAclUserDestUserGroupName |
OCTET STRING |
|
|
hwAclUserSrcModeType |
Integer32 |
|
|
hwAclUserDestModeType |
Integer32 |
|
|
hwAclUserRowStatus |
RowStatus |
|
|
hwAclUserTcpSyncFlag |
Integer32 |
|
|
hwAclUserSrcUserGroupNum |
Integer32 |
|
|
hwAclUserDestUserGroupNum |
Integer32 |
|
HwAclCompileNumGroupEntry |
|
SEQUENCE |
|
|
|
|
hwAclCompileNumGroupStatus |
INTEGER |
|
HwAclIpv6BasicRuleEntry |
|
SEQUENCE |
|
|
|
|
hwAclIpv6BasicAclNum |
Integer32 |
|
|
hwAclIpv6BasicSubitem |
Unsigned32 |
|
|
hwAclIpv6BasicAct |
INTEGER |
|
|
hwAclIpv6BasicSrcIp |
Ipv6Address |
|
|
hwAclIpv6BasicSrcPrefix |
Integer32 |
|
|
hwAclIpv6BasicTimeRangeIndex |
Integer32 |
|
|
hwAclIpv6BasicFragment |
INTEGER |
|
|
hwAclIpv6BasicLog |
TruthValue |
|
|
hwAclIpv6BasicEnable |
EnabledStatus |
|
|
hwAclIpv6BasicCount |
Counter64 |
|
|
hwAclIpv6BasicVrfName |
OCTET STRING |
|
|
hwAclIpv6BasicRowStatus |
RowStatus |
|
|
hwAclIpv6BasicDescription |
OCTET STRING |
|
|
hwAclIpv6BasicSrcMask |
Ipv6Address |
|
HwAclIpv6AdvancedRuleEntry |
|
SEQUENCE |
|
|
|
|
hwAclIpv6AdvancedAclNum |
Integer32 |
|
|
hwAclIpv6AdvancedSubitem |
Unsigned32 |
|
|
hwAclIpv6AdvancedAct |
INTEGER |
|
|
hwAclIpv6AdvancedProtocol |
Integer32 |
|
|
hwAclIpv6AdvancedSrcIp |
Ipv6Address |
|
|
hwAclIpv6AdvancedSrcPrefix |
Integer32 |
|
|
hwAclIpv6AdvancedSrcOp |
INTEGER |
|
|
hwAclIpv6AdvancedSrcPort1 |
Integer32 |
|
|
hwAclIpv6AdvancedSrcPort2 |
Integer32 |
|
|
hwAclIpv6AdvancedDestIp |
Ipv6Address |
|
|
hwAclIpv6AdvancedDestPrefix |
Integer32 |
|
|
hwAclIpv6AdvancedDestOp |
INTEGER |
|
|
hwAclIpv6AdvancedDestPort1 |
Integer32 |
|
|
hwAclIpv6AdvancedDestPort2 |
Integer32 |
|
|
hwAclIpv6AdvancedPrecedence |
Integer32 |
|
|
hwAclIpv6AdvancedTos |
Integer32 |
|
|
hwAclIpv6AdvancedDscp |
Integer32 |
|
|
hwAclIpv6AdvancedEstablish |
TruthValue |
|
|
hwAclIpv6AdvancedTimeRangeIndex |
Integer32 |
|
|
hwAclIpv6AdvancedIcmpType |
Integer32 |
|
|
hwAclIpv6AdvancedIcmpCode |
Integer32 |
|
|
hwAclIpv6AdvancedFragment |
INTEGER |
|
|
hwAclIpv6AdvancedLog |
TruthValue |
|
|
hwAclIpv6AdvancedEnable |
EnabledStatus |
|
|
hwAclIpv6AdvancedCount |
Counter64 |
|
|
hwAclIpv6AdvancedVrfName |
OCTET STRING |
|
|
hwAclIpv6AdvancedRowStatus |
RowStatus |
|
|
hwAclIpv6AdvancedDescription |
OCTET STRING |
|
|
hwAclIpv6AdvancedSrcMask |
Ipv6Address |
|
|
hwAclIpv6AdvancedDestMask |
Ipv6Address |
|
|
hwAclIpv6AdvancedProtocolNew |
Integer32 |
|
HwAclEthernetFrameRuleEntry |
|
SEQUENCE |
|
|
|
|
hwAclEthernetFrameAclNum |
Integer32 |
|
|
hwAclEthernetFrameSubitem |
Unsigned32 |
|
|
hwAclEthernetFrameAct |
INTEGER |
|
|
hwAclEthernetFrameType |
Integer32 |
|
|
hwAclEthernetFrameTypeMask |
Integer32 |
|
|
hwAclEthernetFrameSrcMac |
MacAddress |
|
|
hwAclEthernetFrameSrcMacMask |
MacAddress |
|
|
hwAclEthernetFrameDstMac |
MacAddress |
|
|
hwAclEthernetFrameDstMacMask |
MacAddress |
|
|
hwAclEthernetFrameTimeRangeIndex |
Integer32 |
|
|
hwAclEthernetFrameLog |
TruthValue |
|
|
hwAclEthernetFrameEnable |
EnabledStatus |
|
|
hwAclEthernetFrameCount |
Counter64 |
|
|
hwAclEthernetFrameRowStatus |
RowStatus |
|
|
hwAclEthernetFrameEncapType |
INTEGER |
|
|
hwAclEthernetFrameDoubleTag |
TruthValue |
|
|
hwAclEthernetFrameVlanId |
Integer32 |
|
|
hwAclEthernetFrameVlanIdMask |
Integer32 |
|
|
hwAclEthernetFrameCVlanId |
Integer32 |
|
|
hwAclEthernetFrameCVlanIdMask |
Integer32 |
|
|
hwAclEthernetFrameRule8021p |
Integer32 |
|
|
hwAclEthernetFrameRuleCVlan8021p |
Integer32 |
|
|
hwAclEthernetFrameDescription |
OCTET STRING |
|
HwAclAppliedEntry |
|
SEQUENCE |
|
|
|
|
hwAclAppliedOperation |
INTEGER |
|
|
hwAclAppliedScopeType |
INTEGER |
|
|
hwAclAppliedScopeIndex |
Integer32 |
|
|
hwAclAppliedDirection |
INTEGER |
|
|
hwAclAppliedAclNum |
Integer32 |
|
|
hwAclAppliedSubitem |
Integer32 |
|
|
hwAclAppliedAclNum2 |
Integer32 |
|
|
hwAclAppliedSubitem2 |
Integer32 |
|
|
hwAclAppliedStatMode |
INTEGER |
|
|
hwAclAppliedStatCount |
Counter64 |
|
|
hwAclAppliedLimitCir |
Integer32 |
|
|
hwAclAppliedLimitPir |
Integer32 |
|
|
hwAclAppliedLimitCbs |
Integer32 |
|
|
hwAclAppliedLimitPbs |
Integer32 |
|
|
hwAclAppliedLimitGreenAction |
INTEGER |
|
|
hwAclAppliedLimitGreenValue |
Integer32 |
|
|
hwAclAppliedLimitYellowAction |
INTEGER |
|
|
hwAclAppliedLimitYellowValue |
Integer32 |
|
|
hwAclAppliedLimitRedAction |
INTEGER |
|
|
hwAclAppliedLimitRedValue |
Integer32 |
|
|
hwAclAppliedMirrObservedPort |
Integer32 |
|
|
hwAclAppliedMirrRspanVlan |
Integer32 |
|
|
hwAclAppliedRedirectIfIndex |
Integer32 |
|
|
hwAclAppliedRedirectIpAddr |
IpAddress |
|
|
hwAclAppliedRedirectIpv6Addr |
Ipv6Address |
|
|
hwAclAppliedRemarkVlan |
Integer32 |
|
|
hwAclAppliedRemarkCVlan |
Integer32 |
|
|
hwAclAppliedRemark8021p |
Integer32 |
|
|
hwAclAppliedRemarkDscp |
Integer32 |
|
|
hwAclAppliedRemarkIpPre |
Integer32 |
|
|
hwAclAppliedRemarkLocalPre |
Integer32 |
|
|
hwAclAppliedRemarkMacAddr |
MacAddress |
|
|
hwAclAppliedIsIPv6Acl |
TruthValue |
|
|
hwAclAppliedRowStatus |
RowStatus |
|
HwAclIpv6NumGroupEntry |
|
SEQUENCE |
|
|
|
|
hwAclIpv6NumGroupAclNum |
Integer32 |
|
|
hwAclIpv6NumGroupMatchOrder |
INTEGER |
|
|
hwAclIpv6NumGroupSubitemNum |
Counter32 |
|
|
hwAclIpv6NumGroupCountClear |
INTEGER |
|
|
hwAclIpv6NumGroupAclName |
OCTET STRING |
|
|
hwAclIpv6NumGroupDescription |
OCTET STRING |
|
|
hwAclIpv6NumGroupAclType |
INTEGER |
|
|
hwAclIpv6NumGroupRowStatus |
RowStatus |
|
|
hwAclIpv6NumGroupStep |
Integer32 |
|
HwAclIpv6IfRuleEntry |
|
SEQUENCE |
|
|
|
|
hwAclIpv6IfAclNum |
Integer32 |
|
|
hwAclIpv6IfSubitem |
Unsigned32 |
|
|
hwAclIpv6IfAct |
INTEGER |
|
|
hwAclIpv6IfIndex |
Integer32 |
|
|
hwAclIpv6IfAny |
TruthValue |
|
|
hwAclIpv6IfTimeRangeIndex |
Integer32 |
|
|
hwAclIpv6IfLog |
TruthValue |
|
|
hwAclIpv6IfEnable |
TruthValue |
|
|
hwAclIpv6IfCount |
Counter64 |
|
|
hwAclIpv6IfRowStatus |
RowStatus |
|
hwAcl |
1.3.6.1.4.1.2011.5.1 |
The HUAWEI-ACL-MIB contains objects to configure ACL module,
including ACL group, rule and acl accelerate,
and query the current ACL configuration and status.
This MIB module objects indicate hwAclNumGroupTable, hwAclBasicRuleTable,
hwAclAdvanceRuleTable, hwAclIfRuleTable, hwAclEthernetFrameRuleTable,
hwAclIpv6BasicRuleTable, hwAclIpv6AdvanceRuleTable, hwAclIpv6IfRuleTable,
hwAclCompileEnableFlag, hwAclCompileNumGroupTable,
hwAclIpv6NumGroupTable and acl trap.
To filter data packets, a series of rules need to be configured
on the device. These rules are defined by ACL (Access Control List),
which are a series of sequential rules consisting of rule
permit or deny statements. The rules are described by source
address, destination address and port number of data packets.
ACL classifies data packets through these device interface applied
rules, by which the device decides which packets can be received
and which should be rejected. |
MODULE-IDENTITY |
|
|
|
hwAclNumGroupEntry |
1.3.6.1.4.1.2011.5.1.1.2.1 |
An entry containing characters of an acl group |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclNumGroupEntry |
|
|
hwAclBasicRuleEntry |
1.3.6.1.4.1.2011.5.1.1.4.1 |
Each entry is a rule of basic acl. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclBasicRuleEntry |
|
|
hwAclBasicFragments |
1.3.6.1.4.1.2011.5.1.1.4.1.7 |
The object indicates the type of the packet.
0: fragmentSubseq, indicating that the packet is a subsequent fragment
1: fragment, indicating that the packet is a fragment
2: nonFragment, indicating that the packet is not a fragment
3: nonSubseq, indicating that the packet is not a subsequent fragment
4: fragmentSpeFirst, indicating that the packet is the first fragment
255: none, invalid value
This object cannot be modified once a rule is created. |
Status: current |
Access: read-create |
OBJECT-TYPE |
|
|
|
|
INTEGER |
fragmentSubseq(0), fragment(1), nonFragment(2), nonSubseq(3), fragmentSpeFirst(4), none(255) |
|
hwAclAdvancedRuleEntry |
1.3.6.1.4.1.2011.5.1.1.5.1 |
Each entry contains a rule of advanced acl group. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclAdvancedRuleEntry |
|
|
hwAclAdvancedFragments |
1.3.6.1.4.1.2011.5.1.1.5.1.22 |
The object indicates the type of the packet.
0: fragmentSubseq, indicating that the packet is a subsequent fragment
1: fragment, indicating that the packet is a fragment
2: nonFragment, indicating that the packet is not a fragment
3: nonSubseq, indicating that the packet is not a subsequent fragment
4: fragmentSpeFirst, indicating that the packet is the first fragment
255: none, invalid value
This object cannot be modified once a rule is created. |
Status: current |
Access: read-create |
OBJECT-TYPE |
|
|
|
|
INTEGER |
fragmentSubseq(0), fragment(1), nonFragment(2), nonSubseq(3), fragmentSpeFirst(4), none(255) |
|
hwAclIfRuleEntry |
1.3.6.1.4.1.2011.5.1.1.6.1 |
Each entry contains a rule of interface-based acl group. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclIfRuleEntry |
|
|
hwAclUserRuleEntry |
1.3.6.1.4.1.2011.5.1.1.7.1 |
Each entry contains a rule of user acl group. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclUserRuleEntry |
|
|
hwAclCompileNumGroupEntry |
1.3.6.1.4.1.2011.5.1.1.11.1 |
The entry of Acl-number-group compiler extended table |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclCompileNumGroupEntry |
|
|
hwAclIpv6BasicRuleEntry |
1.3.6.1.4.1.2011.5.1.1.12.1 |
Each entry is a rule of ipv6 basic acl. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclIpv6BasicRuleEntry |
|
|
hwAclIpv6AdvancedRuleEntry |
1.3.6.1.4.1.2011.5.1.1.13.1 |
Each entry contains a rule of ipv6 advanced acl group. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclIpv6AdvancedRuleEntry |
|
|
hwAclEthernetFrameRuleEntry |
1.3.6.1.4.1.2011.5.1.1.14.1 |
Each entry contains a rule of ethernet-frame-based acl group. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclEthernetFrameRuleEntry |
|
|
hwAclAppliedEntry |
1.3.6.1.4.1.2011.5.1.1.15.1 |
Each entry contains a applied ACL. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclAppliedEntry |
|
|
hwAclAppliedOperation |
1.3.6.1.4.1.2011.5.1.1.15.1.1 |
The actions taken when packets conforming or exceeding the configured. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
INTEGER |
filter(1), limit(2), mirror(3), redirectCpu(4), redirectInterface(5), redirectIpNextHop(6), redirectIpv6NextHop(7), remark8021p(8), remarkDscp(9), remarkIpPrecedence(10), remarkLocalPrecedence(11), remarkVlanId(12), remarkCVlanId(13), remarkDestMac(14), statistic(15) |
|
hwAclIpv6NumGroupEntry |
1.3.6.1.4.1.2011.5.1.1.16.1 |
An entry containing characters of an IPv6 ACL group. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclIpv6NumGroupEntry |
|
|
hwAclIpv6IfRuleEntry |
1.3.6.1.4.1.2011.5.1.1.17.1 |
Each entry contains a rule of interface-based acl6 group. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclIpv6IfRuleEntry |
|
|
hwAclMplsRuleEntry |
1.3.6.1.4.1.2011.5.1.1.18.1 |
Each entry is a rule of mpls acl. |
Status: current |
Access: not-accessible |
OBJECT-TYPE |
|
|
|
|
HwAclMplsRuleEntry |
|
|
hwAclResourceTrapsEntry |
1.3.6.1.4.1.2011.5.1.2.2.1.1.4 |
OBJECT IDENTIFIER |
|
|
|