4-7
To do…
Use the command…
Remarks
Enter system view
system-view
––
Create an IPv6 basic
ACL view and enter its
view
acl ipv6 number
acl6-number
[
name
acl6-name
]
[
match-order
{
auto
|
config
} ]
Required
By default, no ACL exists.
IPv6 basic ACLs are numbered in the range 2000
to 2999.
You can use the
acl
ipv6
name
acl6-name
command to enter the view of an existing named
IPv6 ACL.
Configure a description
for the IPv6 basic ACL
description
text
Optional
By default, an IPv6 basic ACL has no ACL
description.
Set the rule numbering
step
step
step-value
Optional
5 by default
Create or edit a rule
rule
[
rule-id
] {
deny
|
permit
}
[
fragment
|
logging
|
source
{
ipv6-address
prefix-length |
ipv6-address
/
prefix-length
|
any
} |
time-range
time-range-name
] *
Required
By default, an IPv6 basic ACL does not contain
any rule.
To create or edit multiple rules, repeat this step.
The
logging
keyword takes effect only when the
module using the ACL supports logging.
Configure or edit a rule
description
rule
rule-id comment
text
Optional
By default, an IPv6 basic ACL rule has no rule
description.
Configuring an Advanced ACL
Configuring an IPv4 advanced ACL
IPv4 advanced ACLs match packets based on source and destination IP addresses, protocols over IP,
and other protocol header information, such as TCP/UDP source and destination port numbers, TCP
flags, ICMP message types, and ICMP message codes.
IPv4 advanced ACLs also allow you to filter packets based on three priority criteria: type of service (ToS),
IP precedence, and differentiated services codepoint (DSCP) priority.
Compared with IPv4 basic ACLs, IPv4 advanced ACLs allow of more flexible and accurate filtering.
Follow these steps to configure an IPv4 advanced ACL:
To do…
Use the command…
Remarks
Enter system view
system-view
––
Create an IPv4 advanced
ACL and enter its view
acl number
acl-number
[
name
acl-name
]
[
match-order
{
auto
|
config
} ]
Required
By default, no ACL exists.
IPv4 advanced ACLs are numbered in the
range 3000 to 3999.
You can use the
acl
name
acl-name
command to enter the view of an existing
named IPv4 ACL.
Configure a description for
the IPv4 advanced ACL
description
text
Optional
By default, an IPv4 advanced ACL has no
ACL description.