Configuring An Ipv6 Advanced Acl - HP 6125G Configuration Manual

Acl and qos configuration guide
Hide thumbs Also See for 6125G:
Table of Contents

Advertisement

Step
5.
Create or edit a
rule.
6.
Add or edit a
rule comment.
7.
Add or edit a
rule range
remark.
8.
Enable counting
ACL rule
matches
performed in
hardware.

Configuring an IPv6 advanced ACL

IPv6 advanced ACLs match packets based on the source IPv6 addresses, destination IPv6 addresses,
packet priorities, protocols carried over IPv6, and other protocol header fields such as the TCP/UDP
source port number, TCP/UDP destination port number, ICMPv6 message type, and ICMPv6 message
code.
Compared to IPv6 basic ACLs, IPv6 advanced ACLs allow more flexible and accurate filtering.
Configuration restrictions and guidelines
When the protocol argument takes 43, 44, 51, or 60, the ACL cannot function on for the outbound QoS
application.
Configuration procedure
To configure an IPv6 advanced ACL:
Command
rule [ rule-id ] { deny | permit }
protocol [ { { ack ack-value | fin
fin-value | psh psh-value | rst
rst-value | syn syn-value | urg
urg-value } * | established } |
counting | destination
{ dest-addr dest-wildcard | any }
| destination-port operator
port1 [ port2 ] | dscp dscp |
fragment | icmp-type
{ icmp-type [ icmp-code ] |
icmp-message } | precedence
precedence | source { sour-addr
sour-wildcard | any } |
source-port operator port1
[ port2 ] | time-range
time-range-name | tos tos |
vpn-instance
vpn-instance-name ] *
rule rule-id comment text
rule [ rule-id ] remark text
hardware-count enable
7
Remarks
By default, an IPv4 advanced ACL does not
contain any rule.
If an IPv4 advanced ACL is for QoS traffic
classification or packet filtering, do not specify the
vpn-instance keyword or specify neq for the
operator argument.
The counting keyword (even if specified) does not
take effect for QoS traffic classification.
Optional.
By default, no rule comments are configured.
Optional.
By default, no rule range remarks are configured.
Optional.
Disabled by default.
This command is available only on the S3100V2-EI
switches.
When the ACL is referenced by a QoS policy, this
command does not take effect.

Advertisement

Table of Contents
loading

This manual is also suitable for:

3600 v2 series6125 blade switch series

Table of Contents