1-6
The name of an IPv6 ACL must be unique among IPv6 ACLs. However, an IPv6 ACL and an IPv4 ACL
can share the same name.
IPv6 ACL Match Order
Similar to IPv4 ACLs, IPv6 ACLs are sequential collections of rules defined with different matching
parameters. The order in which a packet is matched against the rules in an IPv6 ACL may affect how the
packet is handled.
Like in IPv4 ACLs, the following two match orders are available in IPv6 ACLs:
z
config
: where rules are compared against in the order in which they are configured.
z
auto
: where depth-first match is performed.
Depth-first match for a basic IPv6 ACL
The following shows how your switch performs depth-first match in a basic IPv6 ACL:
1) Sort rules by source IPv6 address prefix first and compare packets against the rule configured with
a longer prefix for the source IPv6 address.
2) In case of a tie, compare packets against the rule configured first.
Depth-first match for an advanced IPv6 ACL
The following shows how your switch performs depth-first match in an advanced IPv6 ACL:
1) Look at the protocol type field in the rules first. A rule with no limit to the protocol type (that is,
configured with the
ipv6
keyword) has the lowest precedence. Rules each of which has a single
specified protocol type are of the same precedence level. Compare packets against the rule with
the highest precedence.
2) In case of a tie, look at the source IPv6 address prefixes. Then, compare packets against the rule
configured with a longer prefix for the source IPv6 address.
3) If the prefix lengths for the source IPv6 addresses are the same, look at the destination IPv6
address prefixes. Then, compare packets against the rule configured with a longer prefix for the
destination IPv6 address.
4) If the prefix lengths for the destination IPv6 addresses are the same, look at the Layer 4 port
number ranges, namely the TCP/UDP port number ranges. Then compare packets against the rule
configured with the smaller port number range.
5) If the port number ranges are the same, compare packets against the rule configured first.
The comparison of a packet against an ACL stops once a match is found. The packet is then processed
as per the rule.
IPv6 ACL Step
Refer to
IPv4 ACL Step
.
Effective Period of an IPv6 ACL
Refer to
Effective Period of an IPv4 ACL
.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...