C613-50066-01 REV A
Command Reference for IE200 Series Industrial Managed PoE+ Switches
765
AlliedWare Plus™ Operating System - Version 5.4.5I-0.x
IP
V
6 H
ARDWARE
A
CCESS
C
ONTROL
L
IST
(ACL) C
OMMANDS
(
IPV
6
ACCESS
-
LIST
NAMED
TCP UDP
FILTER
)
(ipv6 access-list named TCP UDP filter)
Overview
Use this ACL filter to add a filter entry for an IPv6 source and destination address
and prefix, with TCP (Transmission Control Protocol) or UDP (User Datagram
Protocol) source and destination ports specified, to the current named IPv6
access-list. If a sequence number is specified, the new entry is inserted at the
specified location. Otherwise, the new entry is added at the end of the access-list.
Note that specifying the
send-to-cpu
parameter could result in EPSR healthcheck
messages and other control packets being dropped.
The
no
variant of this command removes a filter entry for an IPv6 source and
destination address and prefix, with TCP or UDP source and destination ports
specified, from the current named IPv6 access-list. You can specify the filter entry
for removal by entering either its sequence number, or its filter entry profile.
Syntax
[<
sequence-number
>]{deny|permit|send-to-cpu} {tcp|udp}
{<
ipv6-source-prefix/prefix-length
>|<
ipv6-source-address
>
<
ipv6-source-wildcard
>|host <
ipv6-source-host
>|any} eq
<sourceport>
{<
ipv6-destination-prefix/prefix-length
>|<
ipv6-destination-add
ress
> <
ipv6-destination-wildcard
>|host
<
ipv6-destination-host
>|any} eq
<destport>
no {deny|permit|send-to-cpu} {tcp|udp}
{<
ipv6-source-prefix/prefix-length
>|<
ipv6-source-address
>
<
ipv6-source-wildcard
>|host <
ipv6-source-host
>|any} eq
<sourceport>
{<
ipv6-destination-prefix/prefix-length
>|<
ipv6-destination-add
ress
> <
ipv6-destination-wildcard
>|host
<
ipv6-destination-host
>|any} eq
<destport>
no <
sequence-number
>
Parameter
Description
<
sequence-number
>
<1-65535>The sequence number for
the filter entry of the selected
access control list.
deny
Specify packets to reject.
permit
Specifies the packets to permit.
send-to-cpu
Specifies the packets to send to the CPU.
Specifying this parameter could result in EPSR
healthcheck messages and other control packets
being dropped.
tcp
Specifies a TCP packet.
udp
Specifies a UDP packet.
<
ipv6-source-prefix/
prefix-length
>
Specifies the source address with mask.
The IPv6 address prefix uses the format
X:X::/prefix-length. The prefix-length is usually set
between 0 and 64.