Configuration Guide
3. ACLv6
Version 7.2
13
Security Setup
3
ACLv6
The device supports ACL for the IPv6 protocol. Configuration rules are the same as for IPv4.
Table 3-1: ACLv6 Commands
Command
Description
# configure data
Configuration of ACLs is in the data level.
(config-data)# ipv6 access-list
[extended or standard] [Name or
number]
Accesses the ACL with the [name or number]
configuration level.
(config-data)# [line number]
[deny or permit] <protocol>
<source> <source port>
<destination> <destination port>
<mode> [log]
[line number]: Every line starts with a line
number. This defines the number of this line.
(from Version 6.8).
[deny or permit]: connection using this rule is
denied or permitted using.
<protocol>: connection is matched using
one of the protocols: tcp, udp, ah, esp, gre,
icmp, igmp, ip or manually selected using a
number, 0 to 255, that represents the
protocol field of the IP packet.
<source>: selects the source. The source
can be selected as a single host IP address,
range of IP addresses with mask or local
address. It also can be "any" address.
Range of IP addresses can be defined using
a wildcard.
<source port>: source can be matched using
TCP or UDP port. The <source port> can be
omitted.
<destination>: selects the destination. The
destination can be selected as a single host
IP address, range of IP addresses with
mask or local address. It also can be "any"
address. Range of IP addresses can be
defined using a wildcard.
<destination port>: destination can be
matched using TCP or UDP port. The
<destination port> can be omitted.
<mode>: the mode of the ACL. If the
keyword "established" is used, the ACL is
connection aware. If the keyword "stateless"
is used, the ACL is connectionless. The
keyword "dscp" can be used to match the
DSCP field of the IP packet. By default, the
ACL is connection aware. The <mode> can
be omitted.
[LOG]: if the log keyword is used, if a packet
matches the rule, the event is logged and a
counter will increment in the
show
command.
# sh data access-lists
Displays configured ACLs.
(config-data)# no access-list
<Name>
Deletes the ACL with the name <Name>.
Содержание Mediant 500L MSBR
Страница 2: ......
Страница 4: ...Mediant MSBRs 4 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 8: ...Mediant MSBRs 8 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 12: ...Mediant MSBRs 12 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 16: ...Mediant MSBRs 16 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 18: ...Mediant MSBRs 18 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 24: ...Mediant MSBRs 24 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 28: ...Mediant MSBRs 28 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 54: ...Mediant MSBRs 54 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 62: ...Mediant MSBRs 62 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 72: ...Mediant MSBRs 72 Document LTRT 31828 Security Setup This page is intentionally left blank...