Checking The Configuration - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

11 ACL Configuration
Step 2 Run:
acl ipv6 [ number ] acl6-number [ match-order { auto | config } ]
An advanced ACL6 is created.
The acl6-number value of an advanced ACL6 ranges from 3000 to 3999.
match-order indicates the match order of ACL6 rules.
l
l
If match-order is not used, the match order is config.
Step 3 Perform the following steps as required to configure rules for the ACL6:
You can configure the advanced ACL6 on the S9300 according to the type of the protocol carried
by IP. The parameters vary according to the protocol type.
l
l
l
----End

11.4.6 Checking the Configuration

Prerequisite
The configurations of the ACL6 are complete.
Procedure
l
l
----End
11-12
auto indicates that the ACL rules are matched on the basis of depth first principle.
config: indicates that the rules are matched on the basis of the configuration order.
When protocol is TCP or UDP, run:
rule [ rule-id ] { deny | permit } protocol [ destination { destination-ipv6-address prefix-
length | destination-ipv6-address/prefix-length | any } | destination-port operator port |
fragment | precedence precedence | source { source-ipv6-address prefix-length | source-
ipv6-address/prefix-length | any } | source-port operator port | time-range time-name |
*
tos tos ]
When protocol is ICMPv6, run:
rule [ rule-id ] { deny | permit } protocol [ destination { destination-ipv6-address prefix-
length | destination-ipv6-address/prefix-length | any } | fragment | icmpv6-type { icmp6-
type-name | icmp6-type icmp6-code | precedence precedence | source { source-ipv6-
address prefix-length | source-ipv6-address/prefix-length | any } | time-range time-name |
*
tos tos ]
When protocol is not TCP, UDP, or ICMPv6, run:
rule [ rule-id ] { deny | permit } protocol [ destination { destination-ipv6-address prefix-
length | destination-ipv6-address/prefix-length | any } | fragment | precedence
precedence | source { source-ipv6-address prefix-length | source-ipv6-address/prefix-
length | any } | time-range time-name | tos tos ]
Run the display acl ipv6 { acl6-number | all } command to view the rules of the ACL6.
Run the display time-range { all | time-name } command to view information about the
time range.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
*
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents