Configuring An Advanced Ipv6 Acl - 3Com S7906E Configuration Manual

S7900e family release 6600 series
Hide thumbs Also See for S7906E:
Table of Contents

Advertisement

Configuring an Advanced IPv6 ACL

Advanced ACLs filter packets based on the source IPv6 address, destination IPv6 address, protocol
carried on IPv6, and other protocol header fields such as the TCP/UDP source port, TCP/UDP
destination port, ICMP message type, and ICMP message code.
Advanced IPv6 ACLs are numbered in the range 3000 to 3999. Compared with basic IPv6 ACLs, they
allow of more flexible and accurate filtering.
Configuration Prerequisites
If you want to reference a time range to a rule, define it with the time-range command first.
Configuration Procedure
Follow these steps to configure an advanced IPv6 ACL:
To do...
Enter system view
Create
and
advanced IPv6 ACL
view
Create or modify a
rule
Set a rule numbering
step
Create
an
description
Create
a
description
Use the command...
system-view
enter
acl ipv6 number acl6-number [ name
acl6-name ] [ match-order { auto |
config } ]
rule [ rule-id ] { deny | permit } protocol
[ { established | { ack ack-value | fin
fin-value | psh psh-value | rst rst-value |
syn syn-value | urg urg-value } * } |
destination
{
dest/dest-prefix
destination-port
[ port2 ] | dscp dscp | fragment |
icmpv6-type
icmpv6-code | icmpv6-message } |
logging | source { source source-prefix
|
source/source-prefix
source-port operator port1 [ port2 ] |
time-range time-range-name ] *
step step-value
ACL
description text
rule
rule rule-id comment text
dest
dest-prefix
|
|
any
}
|
operator
port1
{
icmpv6-type
|
any
}
|
3-3
Remarks
––
Required
The default match order is
config.
If you specify a name for an IPv6
ACL when creating the ACL, you
can use the acl ipv6 name
acl6-name command to enter
the view of the ACL later.
Required
To create multiple rules, repeat
this step.
Note that if the ACL is to be
referenced by a QoS policy for
traffic classification, the logging
and fragment keywords are not
supported and the operator
argument cannot be:
neq, if the policy is for the
inbound traffic,
gt, lt, neq or range, if the
policy is for the outbound
traffic.
Optional
The default step is 5.
Optional
By
default,
no
IPv6
description is present.
Optional
By default, no rule description is
present.
ACL

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

This manual is also suitable for:

S7910eS7906e-vS7903eS7903e-sS7902e

Table of Contents