Operation Manual – ACL
H3C S3610&S5510 Series Ethernet Switches
Chapter 3 IPv6 ACL Configuration
3-5
z
You may use the
display acl
command to verify rules configured in an ACL. If the
match order for this ACL is
auto
, rules are displayed in the depth-first match order
rather than by rule number.
Caution:
z
You can modify the match order of an IPv6 ACL with the
acl ipv6 number
acl6-number
[
name
acl6-name
]
match-order
{
auto
|
config
} command but only
when it does not contain any rules.
z
The rule specified in the
rule comment
command must have existed.
3.3.3 Configuration Examples
# Create IPv6 ACL 3000 to permit the TCP packets with the source address
2030:5060::9050/64 to pass.
<Sysname> system-view
[Sysname] acl ipv6 number 3000
[Sysname-acl6-adv-3000] rule permit tcp source 2030:5060::9050/64
# Verify the configuration.
[Sysname-acl6-adv-3000] display acl ipv6 3000
Advanced IPv6 ACL 3000, named -none-, 1 rule,
ACL's step is 5
rule 0 permit tcp source 2030:5060::9050/64
3.4 Copying an IPv6 ACL
This feature allows you to copy an existent IPv6 ACL to generate a new one, which is of
the same type and has the same match order, match rules, rule numbering step and
descriptions as the source IPv6 ACL.
3.4.1 Configuration Prerequisites
Make sure that the source IPv4 ACL exists while the destination IPv4 ACL does not.