FAQ-How to Configure the ACL Rule on the MA5680T So That the Priority of the Outer VLAN Can Be Changed Based on the Inner VALN Tag

Publication Date:  2012-07-25
Issue Description
How to configure the ACL rule on the MA5680T so that the priority of the outer VLAN can be changed based on the inner VALN tag? 
Alarm Information
Handling Process
MA5680T(config)#acl 5000 //Create the user-defined acl 5000
MA5680T(config-acl-user-5000)#rule 5 permit 8100 ffff 16
{ <cr>|string<S><2,8>|time-range<K> }:
Run the following command:
rule 5 permit 8100 ffff 16
//Set rule5. In this rule, if the next two bytes of a packet offsetting by 16 bytes are 8100, two tags are contained in the packet and the packet is transmitted.
MA5680T(config-acl-user-5000)#rule 10 permit 0a ff 19
{ <cr>|string<S><2,8>|time-range<K> }:
Run the following command:
rule 10 permit 0a ff 19
//Set rule10. In this rule, if the inner VLAN ID of a packet is 10, the packet is transmitted.
{ inbound<K>|outbound<K> }:inbound
{ user-group<K>|ip-group<K>|link-group<K> }:user-group
{ integer<U><5000,5999> }:5000
{ rule<K>|cos<K>|local-precedence<K>|dscp<K>|ip-precedence<K> }:cos
{ <0-7>|best-effort<K>|background<K>|spare<K>|excellent-effort<K>|controlled-loa
d<K>|video<K>|voice<K>|network-management<K>|from-ipprec<K> }:6
{ local-precedence<K>|port<K>|dscp<K>|ip-precedence<K> }:port
{ frame/slot/port<S><5,15> }:0/3/0
Run the following command:
traffic-priority inbound user-group 5000 cos 6 port 0/3/0
//According to the rule in acl 5000, change the priority of the outer CoS to 6 and deliver it to port 0/3/0 of the LSW in the incoming direction.
Combine the preceding ACL rules. The rule after translation is: If packets sent from port 0/3/0 have two tags and the inner VLAN ID is 10, change the CoS priority of the outer VLAN of the packets to 6. 
Root Cause
If QinQ streams on the MA5680T need to be filtered or matched, the user-defined ACL must be used. The standard or extended ACL does not take effect on the QinQ stream.