Configuring An Advanced Ipv6 Acl - 3Com 4500G Family Configuration Manual

24/48 port
Hide thumbs Also See for 4500G Family:
Table of Contents

Advertisement

Configuring an Advanced IPv6 ACL

Advanced IPv6 ACLs match packets based on the source IPv6 address, destination IPv6 address,
protocol carried over IPv6, and other protocol header fields such as the TCP/UDP source port number,
TCP/UDP destination port number, ICMP message type, and ICMP message code.
Advanced IPv6 ACLs are numbered in the range 3000 to 3999. Compared with basic IPv6 ACLs, they
allow of more flexible and accurate filtering.
Configuration Prerequisites
If you want to reference a time range in a rule, define it with the time-range command first.
Configuration Procedure
Follow these steps to configure an advanced IPv6 ACL:
To do...
Enter system view
Create an advanced
IPv6 ACL and enter
its view
Create or modify a
rule
Set the rule
numbering step
Configure a
description for the
advanced IPv6 ACL
Configure a rule
description
Note that:
Use the command...
system-view
acl ipv6 number acl6-number
[ name acl6-name ] [ match-order
{ auto | config } ]
rule [ rule-id ] { deny | permit }
protocol [ { established | { ack
ack-value | fin fin-value | psh
psh-value | rst rst-value | syn
syn-value | urg urg-value } * } |
destination { dest dest-prefix |
dest/dest-prefix | any } |
destination-port operator port1
[ port2 ] | dscp dscp | fragment |
icmpv6-type { icmpv6-type
icmpv6-code | icmpv6-message } |
logging | source { source
source-prefix |
source/source-prefix | any } |
source-port operator port1
[ port2 ] | time-range
time-range-name ] *
step step-value
description text
rule rule-id comment text
3-3
Remarks
––
Required
The default match order is config.
If you specify a name for an IPv6 ACL
when creating the ACL, you can use
the acl ipv6 name acl6-name
command to enter the view of the ACL
later.
Required
To create or modify multiple rules,
repeat this step.
Note that if the ACL is to be referenced
by a QoS policy for traffic
classification, the logging and
fragment keywords are not supported
and the operator argument cannot be
neq.
Optional
5 by default
Optional
By default, an advanced IPv6 ACL has
no ACL description.
Optional
By default, an IPv6 ACL rule has no
rule description.

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

Table of Contents