Creating Named Ipv6 Address Acls; Table 173. Ipv6 Access-List Commands For Creating Acls - Allied Telesis AT-8100L/8 User Manual

Fast ethernet switches at-8100 series management software command line interface user’s guide alliedware plus version 2.2.5
Hide thumbs Also See for AT-8100L/8:
Table of Contents

Advertisement

Table 172. Named IPv4 ACL TCP Deny Example (Continued)
Command
awplus(config)# ip access-list tcpdeny
awplus(config-ip-acl)# deny tcp
152.12.45.2/32 152.12.45.3/32 vlan 5
Creating Named
IPv6 Address
ACLs

Table 173. IPv6 ACCESS-LIST Commands for Creating ACLs

To do this task
Create an Named IPv6 Address ACL and
enter the IP ACL command mode.
Define a Named IPv6 Address ACL that
filters ICMP packets.
Define a Named IPv6 Address ACL that
filters IP packets based on source and
destination IP addresses.
Define a Named IPv6 Address ACL that
filters traffic flows based on protocol
numbers and source and destination IPv6
addresses.
The Named IPv6 address ACLs are created with the IPv6 ACCESS-LIST
commands. For a description of all the IPv6 ACCESS-LIST commands,
see Chapter 99, "ACL Commands" on page 1555. First, you create the
Named IPv6 ACL with the IPv6 ACCESS-LIST command. It automatically
places you in the IPv6 ACL mode where you can add the filter, as well as
the source and destination IPv6 addresses. In addition, you can classify
tagged packets by assigning a VLAN ID. The time range parameter allows
you to decide when (time and date) filtering begins and ends.
There are six commands for creating Named IPv6 ACLs. The IPv6
ACCESS-LIST command allows you to create a Named IPv6 ACL and
enter the IPv6 ACL command mode. The remaining five commands
provide one command for each filtering criterion of ICMP, IP, Protocol,
TCP, and UDP. The commands are listed in Table 173.
AT-8100 Switch Command Line User's Guide
Create a Named IPv4 ACL called
"tcpdeny" and enter the IP ACL mode.
Allow the filter to deny TCP ingress
packets from source IPv4 address
152.12.45.2/32 to destination IPv4
address 152.12.45.3/32 on VLAN 5.
Use this Command
ipv6 access-list <
list>
action
icmp
scr_ip_address
time-range
dest_ipaddress
[
vid
]
ip
action
scr_ip_address
time-range vlan
dest_ipaddress
[vid]
proto
action
proto_type
scr_ip_address dest_ipaddress
time-range vlan <vid>
Description
ipv6 access
vlan
1537

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents