5000 Series Layer 2/3 Managed Data Center Switch CLI Reference Guide
1211
Parameters
name
Enter access-list name up to 31 characters in length.
starting-sequence-number
The sequence number from which to start. The range is 1—
2147483647. The default is 10.
increment
The amount to increment. The range is 1—2147483647. The default is
10.
Default
The default is 10.
Command Mode
Global Config
12-85 {deny | permit} (IPv6)
This command creates a new rule for the current IPv6 access list. A rule may either deny or permit traffic
according to the specified classification fields. At a minimum, either the every keyword or the protocol,
source address, and destination address values must be specified. The source and destination IPv6
address fields may be specified using the keyword any to indicate a match on any value in that field. The
remaining command parameters are all optional, but the most frequently used parameters appear in the
same relative order as shown in the command format.
Use the
no
command to remove the ACL rule with the specified sequence number from the ACL.
{deny | permit} {every | {{icmpv6 | ipv6 | tcp | udp | 0-255} {source-ipv6-prefix/prefix-length | any |
host source-tpv6-address} [{range {portkey | startport} {portkey | endport} | {eq | neq | lt | gt)
{portkey | 0-65535}] {destination-ipv6-prefix/prefix-length | any | host destination-ipv6-address}
[{range {portkey | startport} {portkey | endport} | {eq | neq | lt | gt} {
portkey | 0-65535
}] [flag [+fin | -
fin] [+syn | -syn] [+rst | -rst] [+psh | -psh] [+ack | -ack] [+urg | -urg] [established]] [flow-label
value] [icmp-type icmp-type [icmp-code icmp-code] | icmp-message icmp-message] [routing]
[fragments] [sequence sequence-number] [dscp dscp]}} [log] [assign-queue queue-id] [{mirror |
redirect} unit/slot/port] [rate-limit rate burst-size]
no sequence-number
Parameters
deny | permit
Specifies whether the IPv6 ACL rule permits or denies the matching
traffic.
every
Specifies to match every packet.
icmpv6 | ipv6 | tcp | udp | 0-
255
Specifies the protocol to match for the IPv6 ACL rule. The current list is:
icmpv6, ipv6, tcp, and udp.
source-ipv6-prefix/prefix-
length | any | host
source-
ipv6-address
Specifies a source IPv6 source address and prefix length to match for
the IPv6 ACL rule.
Specifying any implies specifying “::/0 “
Specifying
host source-ipv6-address
implies matching the specified
IPv6 address.
Содержание 5000 Series
Страница 1: ...Draft 1 2 1 ...
Страница 141: ...5000 Series Layer 2 3 Managed Data Center Switch CLI Reference Guide 135 ...