ProSafe 7000 Managed Switch Software Administration Manual, Release 8.0.3
9-55
Access Control Lists (ACLs)
v1.0, June 2010
e.
Click
Apply
. At the end of this configuration a screen similar to the following displays.
Figure
9-67
Configure IPv6 ACLs
This feature extends the existing IPv4 ACL by providing support for IPv6 packet classification. IPv6 ACLs
classify for Layer 3 IPv6 traffic. Each ACL is a set of up to twelve rules applied to inbound traffic. Each rule
specifies whether the contents of a given field should be used to permit or deny access to the network, and
may apply to one or more of the following fields within a packet:
•
Source IPv6 Prefix
•
Destination IPv6 Prefix
•
Protocol number
•
Source Layer 4 port
•
Destination Layer 4 port
•
DSCP Value
•
Flow Label
Note that the order of the rules is important: when a packet matches multiple rules, the first rule takes
precedence. Also, once you define an ACL for a given port, all traffic not specifically permitted by the ACL
will be denied access.
The script in this section shows you how to set up an IPv6 ACL with the following three rules:
•
Rule-1: Permits every traffic to the destination network 2001:DB8:C0AB:AC14::/64.
•
Rule-2: Permits IPv6 TELNET traffic to the destination network 2001:DB8:C0AB:AC13::/64.
•
Rule-3: Permits IPv6 HTTP traffic to any destination.