3-1
3
IPv6 ACL Configuration
When configuring IPv6 ACLs, go to these sections for information you are interested in:
z
Creating a Time Range
z
Configuring a Basic IPv6 ACL
z
Configuring an Advanced IPv6 ACL
z
Copying an IPv6 ACL
z
Displaying and Maintaining IPv6 ACLs
z
IPv6 ACL Configuration Example
Creating a Time Range
z
Refer to section
Creating a Time Range
Configuring a Basic IPv6 ACL
Basic IPv6 ACLs filter packets based on source IPv6 address. They are numbered in the range 2000 to
2999.
Configuration Prerequisites
If you want to reference a time range to a rule, define it with the
time-range
command first.
Configuration Procedure
Follow these steps to configure a basic IPv6 ACL:
To do…
Use the command…
Remarks
Enter system view
system-view
––
Create and enter basic
IPv6 ACL view
acl ipv6
number
acl6-number
[
name
acl6-name
]
[
match-order
{
auto
|
config
} ]
Required
The default match order is
config
.
If you specify a name for an
IPv6 ACL when creating the
ACL, you can use the
acl
ipv6
name
acl6-name
command to
enter the view of the ACL later.
Create or modify a rule
rule
[
rule-id
] {
deny
|
permit
}
[
fragment
|
logging
|
source
{
ipv6-address
prefix-length |
ipv6-address
/
prefix-length | any
} |
time-range
time-range-name
] *
Required
To create multiple rules, repeat
this step.
Note that the
logging
and
fragment
keywords are not
supported if the ACL is to be
referenced by a QoS policy for
traffic classification.
Summary of Contents for S7906E - Switch
Page 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Page 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Page 598: ...ii...
Page 1757: ...4 9...
Page 1770: ...6 4...
Page 2017: ...2 11 Figure 2 3 SFTP client interface...
Page 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...