Configuring An Ipv6 Object Policy Rule; Applying Object Policies To Zone Pairs - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Configuring an IPv6 object policy rule

You can specify an existing object group in an IPv6 object policy rule for matching target IPv6
packets. If no object group is specified for a rule, the rule applies to all IPv6 packets.
The following object groups can be referenced in a rule for packet matching:
Source IPv6 address object group—Used for matching the source IPv6 addresses of
packets.
Destination IPv6 address object group—Used for matching the destination IPv6 addresses
of packets.
Service object group—Used for matching the service types carried in packets.
VRF instance—Used for matching the MPLS L3VPN instances of packets.
For more information about the object groups, see
To configure an IPv6 object policy rule:
Step
1.
Enter system view.
2.
Enter IPv6 object
policy view.
3.
Configure an IPv6
object policy rule.
4.
(Optional.)
Configure a
description for the
rule.

Applying object policies to zone pairs

You can apply one IPv4 object policy and one IPv6 object policy to each zone pair. Configuration fails
if you apply more than one IPv4 or IPv6 object policy to a zone pair.
To apply an object policy to a zone pair:
Step
1.
Enter system view.
2.
Configure the security
zones.
3.
Create a zone pair
and enter zone pair
view.
Command
system-view
object-policy ipv6 object-policy-name
rule [ rule-id ] { drop | pass } [ [ source-ip
object-group-name | any ] [ destination-ip
object-group-name | any ] [ service
object-group-name | any ] [ vrf vrf-name ]
[ counting ] [ disable ] [ logging ]
[ time-range time-range-name ] ] *
rule rule-id comment text
Command
system-view
security-zone name zone-name
zone-pair security source source-zone-name
destination destination-zone-name
476
"Configuring object
groups."
Remarks
N/A
N/A
By default, no object policy rule
exists.
If you specify a nonexistent
object group, the rule does not
match packets.
By default, an object policy rule
does not have a description.
Remarks
N/A
By default, no security
zone exists.
You can repeat this
command to create
multiple security zones.
By default, no zone pair
exists.
For more information
about this command, see
Fundamentals Command
Reference.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents