Chapter 4 IPv6 ACL Configuration
Parameter
Description
<
rule-id
>
Indicates the unique identity of a rule in the IPv6 ACL table.
This ID determines the sequence of the rule in the IPv6 ACL
table. It ranges from 1 to 2147483644.
If this parameter is not specified, the system inserts the rule
to the end of the table by default and allocates the rule-id
according to the default base and increment.
permit
Indicates that the rule is the permit rule.
deny
Indicates that the rule is the deny rule.
protocol
Indicates the protocol type to be matched, which can be one
of the keywords "tcp", "udp" and "ip", or can be an integer
representing the IP protocol number and ranging from 0
to 255. If this parameter is set to "ip", it indicates that any
protocol type is matched.
source
Indicates the source IPv6 address.
destination
Indicates the destination IPv6 address.
oper
Indicates the port operation type, which can be any of the
keywords "eq", "ge", "le", and "range". If this parameter is set
to "range", two port numbers need to be specified behind
"range".
<
source-port
>
Indicates the source port number ranging from 0 to 255.
<
destination-port
>
Indicates the destination port number ranging from 0 to 255.
dscp
<
value
>
Indicates the DSCP field. The value range is 0-63.
traffic-class
<
value
>
Indicates the traffic-class field. The value range is 0-255.
established, fin, rst, ack, urg, psh, syn
Indicates TCP link establishment. This parameter is valid
for TCP only.
authen, destopts, esp, fragments,
hop-by-hop, routing
Fields in an IPv6 extended header.
The command parameters in step 5 are described as follows:
Parameter
Description
ingress
Indicates that the IPv6 ACL is bound to the ingress direction
of the interface.
egress
Indicates that the IPv6 ACL is bound to the egress direction
of the interface.
Configuring IPv6-MIXED-ACL
To configure the IPv6-MIXED-ACL on ZXR10 5900E, use the following commands:
4-3
SJ-20150114102049-011|2015-01-15 (R1.0)
ZTE Proprietary and Confidential