C613-50170-01 Rev B
Command Reference for x510 Series
1575
AlliedWare Plus™ Operating System - Version 5.4.7-1.x
IP
V
6 H
ARDWARE
A
CCESS
C
ONTROL
L
IST
(ACL) C
OMMANDS
(
NAMED
IP
V
6
HARDWARE
ACL: IP
PROTOCOL
ENTRY
)
(named IPv6 hardware ACL: IP protocol
entry)
Overview
Use this command to add an IP protocol type filter entry to the current IPv6
hardware access-list. The filter will match on IPv6 packets that have the specified
IP protocol number, and the specified IPv6 addresses. You can use the value
any
instead of source or destination IPv6 address if an address does not matter.
The
no
variant of this command removes a filter entry from the current hardware
access-list. You can specify the filter entry for removal by entering either its
sequence number (e.g.
no 100
), or by entering its filter profile without specifying
its sequence number (e.g.
no deny proto 2 2001:0db8::0/64 any
).
You can find the sequence number by running the
Hardware ACLs will
permit
access unless
explicitly denied
by an ACL action.
Syntax
[<
sequence-number
>] <
action
> proto <
1-255
> <
source-addr
>
<
dest-addr
> [vlan <
1-4094
>]
no <
sequence-number
>
no <
action
> proto <
1-255
> <
source-addr
> <
dest-addr
> [vlan
<
1-4094
>]
Table 38-2: Parameters in IP protocol ACL entries
Parameter
Description
<
sequence-
number
>
The sequence number for the filter entry of the selected access
control list, in the range 1-65535.
<action>
The action that the switch will take on matching packets:
deny
Reject packets that match the
source and destination filtering
specified with this command.
permit
Permit packets that match the
source and destination filtering
specified with this command.
copy-to-cpu
Send a copy of matching packets
to the CPU.
copy-to-mirror
Send a copy of matching packets
to the mirror port.
Use the
command
to configure the mirror port.
send-to-mirror
Send matching packets to the
mirror port.
Use the
command
to configure the mirror port.