ZXR10 ZSR V2 Configuration Guide (IPv6)
Command
Function
ZXR10(config)#
show running-config port-acl
[
all
][|{
begin
|
exclude
|
include
}<
key_words
>]
Displays all the IPv6 ACL binding
information (and the IPv4 ACL binding
information as well as if any IPv4 ACL
is bound).
– End of Steps –
20.3 IPv6 ACL Configuration Example
Configuration Description
In the network as shown in
, suppose both PC1 and PC2 send telnet requests
through R2 to R1. R1 expects to receive the login requests of PC1 only but not the login
requests of PC2. Then an ACL can be bound to the ingress direction of the interface
gei-1/3 to filter out the telnet packets from PC2 (or the ACL may be binded to the egress
direction of the interface gei-1/4).
Figure 20-1 IPv6 ACL Configuration Example
In this case, it is only necessary to create one ACL and add the following rule to this ACL:
Deny the telnet packets matching the IP address of PC2 and using the protocol type TCP
and the port type telnet. Then bind the ACL to the ingress direction of the interface gei-1/3
or the egress direction of the interface gei-1/4.
After the above configuration is completed, the requests initiated by PC2 do not reach R1
but are discarded when they reach R2 even if PC2 has not obtained the telnet username
and password of R1. The other communications of R1 and PC2, however, are not be
affected.
Configuration Flow
1.
Enable IPv6 and configure the interface addresses on routers.
2.
First create an ipv6-access-list. During the creation, a customized name can be
assigned to this list but the length of the name shall not exceed 31 characters.
20-4
SJ-20140504150128-018|2014-05-10 (R1.0)
ZTE Proprietary and Confidential