8
Step Command
Remarks
2.
Create an IPv6 advanced
ACL and enter its view.
acl ipv6 advanced
{
acl-number
|
name
acl-name
} [
match-order
{
auto
|
config
} ]
By default, no ACLs exist.
The value range for a numbered
IPv6 advanced ACL is 3000 to
3999.
Use the
acl ipv6 advanced
acl-number
command to enter the
view of a numbered IPv6
advanced ACL.
Use the
acl
ipv6 advanced name
acl-name
command to enter the
view of a named IPv6 advanced
ACL.
3.
(Optional.) Configure a
description for the IPv6
advanced ACL.
description
text
By default, an IPv6 advanced ACL
does not have a description.
4.
(Optional.) Set the rule
numbering step.
step
step-value
[
start
start-value
]
By default, the rule numbering
step is 5 and the start rule ID is 0.
5.
Create or edit a rule.
rule
[
rule-id
] {
deny
|
permit
}
protocol
[ { {
ack
ack-value
|
fin
fin-value
|
psh
psh-value
|
rst
rst-value
|
syn
syn-value
|
urg
urg-value
} * |
established
} |
counting
|
destination
{
dest-address
dest-prefix
|
dest-address/dest-prefix
|
any
} |
destination-port
operator
port1
[
port2
] |
dscp
dscp
|
flow-label
flow-label-value
|
fragment
|
icmp6-type
{
icmp6-type
icmp6-code
|
icmp6-message
} |
logging
|
routing
[
type
routing-type
] |
hop-by-hop
[
type
hop-type
] |
source
{
source-address
source-prefix
|
source-address/source-prefix
|
any
} |
source-port
|
time-range
time-range-name
|
vpn-instance
vpn-instance-name
] *
By default, no IPv6 advanced ACL
rules exist.
The
logging
keyword takes effect
only when the module (for
example, packet filtering) that
uses the ACL supports logging.
If an IPv6 advanced ACL is used
for outbound QoS traffic
classification or packet filtering,
do not specify the
flow-label
parameter.
If an IPv6 advanced ACL is used
for packet filtering, do not specify
the
fragment
keyword.
6.
(Optional.) Add or edit a rule
comment.
rule
rule-id comment
text
By default, no rule comment is
configured.
Configuring a Layer 2 ACL
Layer 2 ACLs, also called "Ethernet frame header ACLs," match packets based on Layer 2 Ethernet
header fields, such as:
•
Source MAC address.
•
Destination MAC address.
•
802.1p priority (VLAN priority).
•
Link layer protocol type.
To configure a Layer 2 ACL:
Summary of Contents for FlexFabric 5940 Series
Page 23: ...17 Figure 3 QoS processing flow ...
Page 84: ...78 Figure 26 MPLS label structure ...
Page 91: ...85 Switch burst mode enable ...