Huawei Quidway S9300 Configuration Manual page 290

Terabit routing switch
Table of Contents

Advertisement

11 ACL Configuration
<Quidway> system-view
[Quidway] sysname S9300-B
[S9300-B] ipv6
[S9300-B] interface loopback 2
[S9300-B-LoopBack2] ipv6 enable
[S9300-B-LoopBack2] ipv6 address 3002::2 64
[S9300-B-LoopBack2] quit
[S9300-B] interface gigabitethernet 1/0/0
[S9300-B-GigabitEthernet1/0/0] port link-type trunk
[S9300-B-GigabitEthernet1/0/0] port trunk allow-pass vlan 10
[S9300-B-GigabitEthernet1/0/0] quit
[S9300-B] interface vlanif 10
[S9300-B-Vlanif10] ipv6 enable
[S9300-B-Vlanif10] ipv6 address 3001::2 64
[S9300-B-Vlanif10] quit
# Ping interface VLANIF 10 of S9300-A from VLANIF 10 of S9300-B.
[S9300-B] ping ipv6 -a 3001::2 3001::1
PING 3001::1 : 56
--- 3001::1 ping statistics ---
The ping succeeds without timeout or abnormal delay.
# Ping interface VLANIF 10 of S9300-A from loopback2 of S9300-B.
[S9300-B] ping ipv6 -a 3002::2 3001::1
PING 3001::1 : 56
--- 3001::1 ping statistics ---
The ping succeeds without timeout or abnormal delay.
Step 2 Create an ACL6 rule and apply the rule to the interface to reject the IPv6 packets from 3001::2.
# Configure S9300-A.
[S9300-A] acl ipv6 number 3001
[S9300-A-acl6-adv-3001] rule deny ipv6 source 3001::2/128
[S9300-A-acl6-adv-3001] quit
[S9300-A] traffic classifier class1
11-24
data bytes, press CTRL_C to break
Reply from 3001::1
bytes=56 Sequence=1 hop limit=64
Reply from 3001::1
bytes=56 Sequence=2 hop limit=64
Reply from 3001::1
bytes=56 Sequence=3 hop limit=64
Reply from 3001::1
bytes=56 Sequence=4 hop limit=64
Reply from 3001::1
bytes=56 Sequence=5 hop limit=64
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/40/80 ms
data bytes, press CTRL_C to break
Reply from 3001::1
bytes=56 Sequence=1 hop limit=64
Reply from 3001::1
bytes=56 Sequence=2 hop limit=64
Reply from 3001::1
bytes=56 Sequence=3 hop limit=64
Reply from 3001::1
bytes=56 Sequence=4 hop limit=64
Reply from 3001::1
bytes=56 Sequence=5 hop limit=64
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 20/36/60 ms
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
time = 80 ms
time = 50 ms
time = 40 ms
time = 30 ms
time = 1 ms
time = 60 ms
time = 30 ms
time = 20 ms
time = 50 ms
time = 20 ms
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents