Chapter 20 IPv6 ACL Configuration
range
: number of port operations, range: 0–65535.
<
source-port
>: indicates that the source port number ranges from 0 to 255.
<
destination-port
>: indicates the destination port number ranges from 0 to 255.
dscp
<
value
>: indicates the DSCP field, range: 0 to 63.
established
: indicates TCP link establishment. This parameter is valid for TCP only.
<
rst
><
ack
><
fin
><
syn
><
psh
><
urg
>: A combination of URG, ACK, PSH, RST, SYN and
FINT flags in a TCP header.
routing, authen, destopts, fragments, hop-by-hop, and esp
: Options: routing header,
authentication header, destination option header, fragment header, Hop-by-Hop
Options Header and ESP Header.
time-range
: binds a specified, existing time-range.
<
base
>: base value of rule-id, indicating the serial number of the first rule after rules
are renumbered successfully. Default: 10, range: 1–2147483644.
<
increment
>: step size of rule-id, which is the difference between two neighboring
rule-ids after rules are renumbered. Default: 10, range: 1–2147483644.
2.
Bind IPv6 ACL to an interface.
Step
Command
Function
1
ZXR10(config)#
ipv6-access-group interface
<
interface-name
>{
ingress
|
egress
}<
acl-name
>
Binds the specified IPv6 ACL
to the specified interface.
ZXR10(config)#
interface
<
interface-name
>
Enters interface configuration
mode.
2
ZXR10(config-if-interface-name)#
ipv6-access-group
{
ingress
|
egress
}<
acl-name
>
Binds the specified IPv6 ACL
in interface configuration
mode.
3.
Verify the configurations.
Command
Function
ZXR10(config)#
show ipv6-access-lists
[
config
|
brief
[
name
<
acl-name
>]|
name
<
acl-name
>[
from
<
from-id
>
to
<
to-id
>]][|<
match-type
><
LINE
>]
Displays the IPv6 ACL list or brief
information.
ZXR10(config)#
show ipv6-access-groups
[{[
by-access-list
<
acl-name
>]
,
[
by-direction
{
ingress
|
egress
}]
,
[
by-interface
<
interface-name
>]}]
Displays the IPv6 ACL binding
information. The information can be
selectively displayed according to the
command parameters.
ZXR10(config)#
show running-config ipv6-acl
[
all
][|{
begin
|
exclude
|
include
}<
key_words
>]
Displays the entire IPv6 ACL
information.
20-3
SJ-20140504150128-018|2014-05-10 (R1.0)
ZTE Proprietary and Confidential