Download Print this page

Dell Force10 TeraScale E Series Reference Manual page 692

Ftos command line, ftos 8.4.2.7

Advertisement

Command
History
Usage
Information
Related
Commands
ipv6 access-group
c e s
Syntax
Parameters
692
|
IPv6 Access Control Lists (IPv6 ACLs)
Version 8.4.2.1
Introduced on the S-Series
Version 8.2.1.0
Introduced on the E-Series ExaScale
Version 7.8.1.0
Introduced on the C-Series
Version 7.4.1.0
Introduced on the E-Series TeraScale
Added
The C-Series cannot count both packets and bytes, so when you enter the count byte options, only
bytes are incremented.
Most ACL rules require one entry in the CAM. However, rules with TCP and UDP port operators (gt,
lt, range) may require more than one entry. The range of ports is configured in the CAM based on
bitmask boundaries; the space required depends on exactly what ports are included in the range.
For example, an ACL rule with TCP port range 4000 - 8000 will use 8 entries in the CAM:
Rule#
Data
1
0000111110100000 1111111111100000 4000
2
0000111111000000 1111111111000000 4032
3
0001000000000000 1111100000000000 4096
4
0001100000000000 1111110000000000 6144
5
0001110000000000 1111111000000000 7168
6
0001111000000000 1111111100000000 7680
7
0001111100000000 1111111111000000 7936
8
0001111101000000 1111111111111111 8000
Total Ports: 4001
But an ACL rule with TCP port lt 1023 takes only one entry in the CAM:
Rule#
Data
1
0000000000000000 1111110000000000 0
Total Ports: 1024
deny
Assign a deny filter for IP traffic.
deny tcp
Assign a deny filter for TCP traffic.
Assign an IPv6 access-group to an interface.
ipv6 access-group access-list-name {in | out} [implicit-permit] [vlan range]
To delete an IPv6 access-group configuration, use the no ipv6 access-group access-list-name
{in} [implicit-permit] [vlan range] command.
access-list-name
in
out
|
monitor
option
Mask
Mask
Enter the name of a configured access list, up to 140 characters.
in
Enter either the keyword
or
(ingress) or outgoing traffic (egress).
From
To
#Covered
4031
32
4095
64
6143
2048
7167
1024
7679
512
7935
256
7999
64
8000
1
From
To
#Covered
1023
1024
out
to apply the IPv6 ACL to incoming traffic

Advertisement

loading