Operation Manual – ACLH3C S3100 Series Ethernet Switches Chapter 1 ACL Configuration1-10[Sysname-acl-ethernetframe-4000] display acl 4000Ethernet frame ACL 4000, 1 ruleAcl's step is 1rule 0 deny cos excellent-effort source 000d-88f5-97ed ffff-ffff-ffff dest0011-4301-991e ffff-ffff-ffff1.3 ACL AssignmentOn an S3100-EI Ethernet switch, you can assign ACLs to the hardware for packetfiltering.As for ACL assignment, the following four ways are available.z Assigning ACLs globally, for filtering the inbound packets on all the ports.z Assigning ACLs to a VLAN, for filtering the inbound packets on all the ports andbelonging to a VLAN.z Assigning ACLs to a port group, for filtering the inbound packets on all the ports ina port group. For information about port group, refer to Port Basic Configuration.z Assigning ACLs to a port, for filtering the inbound packets on a port.You can assign ACLs in the above-mentioned ways as required.Caution:In terms of priority, the ACLs assigned globally, ACLs assigned to a VLAN and ACLsassigned to a port group (or a port) rank in descending order. If a packet matchesmultiple rules in these ACLs and is permitted by some rules but denied by the others,the device permits or denies the packet based on the rule in the ACL with the highestpriority.1.3.1 Assigning an ACL GloballyI. Configuration prerequisitesBefore applying ACL rules to a VLAN, you need to define the related ACLs. Forinformation about defining an ACL, refer to section 1.2.2 Configuring Basic ACL,section 1.2.3 Configuring Advanced ACL, section 1.2.4 Configuring Layer 2 ACL.II. Configure procedureTable 1-5 Assign an ACL globallyOperation Command DescriptionEnter system view system-view —