Chapter 4 IPv6 ACL Configuration
Parameter
Description
<
rule-id
>
Indicates the unique identity of a rule in the ACL. This
ID determines the sequence of the rule. Range: 1 to
2147483646.
If this parameter is not set, the system inserts the rule to the
end of the ACL by default and sets the rule-id according to
the default base and increment.
permit
Keyword indicating that the rule is a permit rule.
deny
Keyword indicating that the rule is a deny rule.
protocol
Protocol type to be matched, which can be set to "tcp", "udp"
or "ip", or an integer representing the IP protocol number
ranging from 0 to 255. If this parameter is set to "ip", it
indicates that any protocol type is matched.
source
Source IPv6 address, in the form of dotted decimal notation
<
source-wildcard
>
Wildcard mask of the source IPv6 address, in the form of
dotted decimal notation.
destination
Destination IPv6 address, in the form of dotted decimal
notation.
<
sdestination-wildcard
>
Wildcard mask of the destination IPv6 address, in the form of
dotted decimal notation.
oper
Port operation type, which can be any of the keywords "eq",
"ge", "le", and "range". If this parameter is set to "range", two
port numbers need to be specified behind "range".
source-port
Source port number, range: 0 to 65535.
destination-port
Destination port number, range: 0 to 65535
precedence
<
value
>
Precedence. Range: 0 to 7
established ,fin,rst,ack,urg,psh,syn
Keywords for TCP link establishment. This parameter is valid
for TCP only.
dscp
<
value
>
DSCP field, range: 0 to 63.
authen,destopts, esp, fragments,
hop-by-hop, routing
IPv6 extension prefix field.
time-tange
Time range.
established
Keyword for TCP link establishment. This parameter is valid
for TCP only.
link-protocol
Type of the level 2 protocol to be matched. Value: 34525.
source-mac
Source MAC address, in the form of dotted hexadecimal
notation.
4-5
SJ-20150114102049-011|2015-01-15 (R1.0)
ZTE Proprietary and Confidential