ZXR10 5900E Series Configuration Guide (IPv6)
Step
Command
Function
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}{
source
|
any
}{
destination
|
any
}[
time-range
<
name
>]
Configures the IPv6 ACL rule
based on the source address.
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}
protocol
{
source
|
any
}{
destination
|
any
}[{
dscp
<
value
>}][
time-range
<
name
>][
traffic-class
<
value
>]
Configures the extended IPv6
ACL rule.
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}
tcp
{
source
|
any
}[
oper
<
source-port
>]{
destination
|
any
}[
oper
<
destination-port
>][{
dscp
<
value
>}][
es
tablish
][
fin
][
psh
][
range
][
rst
][
syn
][
urg
][
time-range
<
name
>][
traffic-class
<
value
>]
Configures the IPv6 ACL rule
based on TCP.
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}
udp
{
source
|
any
}[
oper
<
source-port
>]{
destination
|
any
}[
oper
<
destination-port
>][{
dscp
<
value
>}][
time-range
<
name
>][
traffic-class
<
value
>]
Configures the IPv6 ACL rule
based on UDP.
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}
icmp
{
source
|
any
}{
destination
|
any
}[
icmp-type
|
icmp-code
][{
dscp
<
value
>}][
time-range
<
name
>][
traffic-class
<
value
>]
Configures the IPv6 ACL rule
based on ICMP.
2
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}
protocol
{
source
|
any
}{
destination
|
any
}[
authen
][
destopts
][
esp
][
fragments
][
hop-by-hop
][
routing
][
time-range
<
name
>][
traffic-class
<
value
>]
This configures an ACL with an
IPv6 extended header.
ZXR10(config-ipv6-acl)#
no rule
{<
rule-id
>|
all
}
Deletes the specified IPv6 ACL
rule or all rules.
3
ZXR10(config-ipv6-acl)#
move
<
target-rule-id
><
target-New-rule-id
>
Move the ACL.
ZXR10(config)#
ipv6-access-group
{
interface
<
interface-name
>}{
ingress
|
egress
<
acl-name
>}
Binds the specified IPv6 ACL
to the specified interface.
4
ZXR10(config)#
no ipv6-access-group
{
ingress
|
egress
}
Deletes the bound IPv6 ACL
from the specified interface.
ZXR10(config)#
interface
<
interface-name
>
Enters the interface
configuration mode.
ZXR10(config-if)#
ipv6-access-group
<
interface-name
>{
i
ngress
|
egress
}<
acl-name
>
Binds the specified IPv6 ACL in
interface configuration mode.
5
ZXR10(config-if)#
no ipv6-access-group
{
ingress
|
egress
}
Deletes the bound IPv6 ACL in
interface configuration mode.
The command parameters in step 2 are described as follows:
4-2
SJ-20150114102049-011|2015-01-15 (R1.0)
ZTE Proprietary and Confidential