acl number 3001
nesting 3000                                              /配置嵌套组/
rule 1 deny ip                                           /禁止所有数据包/
acl number 3002
rule 0 permit ip reflect 3000 timeout 300    /配置自反组,单条老化时间的默认值是300/