ZXR10 ZSR V2 Configuration Guide (IPv6)
Step
Command
Function
range
<
0-65535
>
-
<
0-65535
>}][{[
established
]
,
[
rst
<
rst
>]
,
[
ac
k
<
ack
>]
,
[
fin
<
fin
>]
,
[
syn
<
syn
>]
,
[
urg
<
urg
>]
,
[
psh
<
psh
>]}][
d
scp
<
dscp-value
>][{[
routing
]
,
[
authen
]
,
[
destopts
]
,
[
fragment
s
]
,
[
hop-by-hop
]
,
[
esp
]}][
time-range
<
time-range-name
>]
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}[
flowlabel
<
flowlabel-value
>]
udp
{<
source-ip
v6-address
>|
any
}[<
oper
><
source-port
>]{<
destination
-ipv6-address
>|
any
}[<
oper
><
destination-port
>][
dscp
<
dscp-value
>][{[
routing
]
,
[
authen
]
,
[
destopts
]
,
[
fragments
]
,
[
h
op-by-hop
]
,
[
esp
]}][
time-range
<
time-range-name
>]
Configures the IPv6 ACL rule
based on UDP.
ZXR10(config-ipv6-acl)#
rule
[<
rule-id
>]{
permit
|
deny
}[
flowlabel
<
flowlabel-value
>]
icmp
{<
source-ipv6-address
>|
any
}{<
destination-ipv6-address
>|
any
}[{<
icmp-type
>|<
icmp-type-value
>}[<
icmp-code
>]][
dscp
<
dscp-value
>][{[
routing
]
,
[
authen
]
,
[
destopts
]
,
[
fragments
]
,
[
h
op-by-hop
]
,
[
esp
]}][
time-range
<
time-range-name
>]
Configures the IPv6 ACL rule
based on ICMP.
3
ZXR10(config)#
resequence-access-list ipv6
<
acl-name
>[<
base
>[<
increment
>]]
Numbers the rules in the
specified ACL again.
<
rule-id
>: unique identity of a rule in the IPv6 ACL table, range: 1 to 2147483644. This
ID determines the sequence of the rule in the IPv6 ACL table. If this parameter is not
specified, the system inserts the rule at the end of the table by default and allocates
the rule-id according to the default base and increment.
<
0-255
>|
ipv6
|<
protocol-type
>: Indicates the protocol type to be matched, which can
be one of the “tcp”, “udp” and “ip” keywords, or can be an integer representing the IP
protocol number and ranging from 0 to 255. If this parameter is set to “ipv6”, it indicates
that any protocol type is matched.
<
icmp-type
>:
ICMP type,
options:
destination-unreachable,
packet-too-big,
time-exceeded, parameter-problem, echo-request, echo-reply, mld-query, mld-report,
mld-reduction, router-solicitation, router-advertisment, nd-ns, nd-na, redirect and
router-renumbering.
<
icmp-type-value
>: ICMP packet type field, range: 0–255.
<
icmp-code
>: ICMP message type, range: 0 to 255.
<
protocol-type
>: IP protocol type, options: gre, ospf, pim and vrrp.
<
operator
>: port operation, options: eq, ge and le.
<
source-porttype
>: source port type, options: ftp, telnet, smtp, domain, finger, www,
pop2, pop3, bgp and login.
<
destination-porttype
>: destination port type, options: ftp, telnet, smtp, domain, finger,
www, pop2, pop3, bgp and login.
20-2
SJ-20140504150128-018|2014-05-10 (R1.0)
ZTE Proprietary and Confidential