Operation Manual – QoS/ACLH3C S9500 Series Routing Switches Chapter 1 ACL Configuration1-12Table 1-13 Activate ACLOperation CommandActivate ip group ACL packet-filter inbound ip-group { acl-number |acl-name } [ rule rule] [ system-index index] slot slotidDeactivate ip group ACL undo packet-filter inbound ip-group { acl-number |acl-name } [ rule rule ] slot slotidCaution:z The syntax of the QoS/ACL command used for service processor cards(LSB1NATB0 cards in the context of this document) is somewhat different from thatfor interface cards. Refer to related description in the manual.z Before executing the packet-filter command on a service processor card, you mustfirst configure traffic redirection in Ethernet port view to redirect the packets of aspecific VLAN to the service processor card.z Service processor cards do not support Layer 2 ACL.system-index index here is the system index for an ACL rule. When delivering a rule,the system assigns a globally unique index to it, for convenience of later retrieval. Youcan also assign a system index for it when delivering an ACL rule with this command.However, you are not recommended to assign a system index if not urgently necessary.Note:If you remove the card with QoS/ACL configured when the system operates, thecorresponding system index value is automatically released and is then used for anewly delivered flow rule. Once the system index value is occupied, the originalconfiguration cannot be restored even you insert the removed card back.1.3 Displaying and Debugging ACL ConfigurationsAfter these configurations are completed, you can use the display command in anyview to view ACL running to check configuration result. You can clear ACL statisticsusing the display command in user view.