Korenix Technology Co., Ltd.
Industrial
Layer 3 Managed Ethernet Switch
_____________________________________________________________________________
Industrial Layer 3 Managed Ethernet SwitchUser Manual
Page: 616/1568
!
6.23.2.3
{deny | permit}
This command creates a new rule for the current IPv6 access list. Each rule is appended to the list of
configured rules for the list.
The
‘no’ form of this command is not supported, since the rules within an IPv6 ACL cannot
be deleted individually. Rather, the entire IPv6 ACL must be deleted and respecified.
An implicit
‘deny all’ IPv6 rule always terminates the access list.
A rule may either deny or permit traffic according to the specified classification fields. At a minimum,
either the
‘every’ keyword or the protocol, source address, and destination address values must be
specified. The source and destination IPv6 address fields may be specified using the keyword
‘any’ to
indicate a match on any value in that field. The remaining command parameters are all optional, but the
most frequently used parameters appear in the same relative order as shown in the command format.
The assign-queue parameter allows specification of a particular hardware queue for handling traffic that
matches this rule. The allowed <queue-id> value is 0-(n-1), where n is the number of user configurable
queues available for the hardware platform. The assign-queue parameter is valid only for a permit rule.
The mirror parameter allows the traffic matching this rule to be copied to the specified <slot/port>, while
the redirect parameter allows the traffic matching this rule to be forwarded to the specified <slot/port>.
The assign-queue and redirect parameters are only valid for a permit rule.
The time-range parameter allows imposing time limitation on the IPv6 ACL rule as defined by the
parameter time-range-name . If a time range with the specified name does not exist and the IPv6 ACL
containing this ACL rule is applied to an interface or bound to a VLAN, then the ACL rule is applied
immediately. If a time range with specified name exists and the IPv6 ACL containing this ACL rule is
applied to an interface or bound to a VLAN, then the ACL rule is applied when the time-range with
specified name becomes active. The ACL rule is removed when the time-range with specified name
becomes inactive.
Syntax
{del-rule-id | deny | permit} {every | {{icmpv6 | ipv6 | tcp | udp | <number>} [log] [time-range
time-range-name] [assign-queue <queue-id>] [{mirror | redirect} <slot/port>] [rule-id]
Default Setting
None
Command Mode
IPv6-Access-List Config