beautypg.com

Permit, deny (extended ipv6 acl) – LevelOne FGL-2870 User Manual

Page 574

background image

Command Line Interface

4-208

4

permit, deny (Extended IPv6 ACL)

This command adds a rule to an Extended IPv6 ACL. The rule sets a filter condition
for packets with specific destination IP addresses, next header type, or flow label.
Use the no form to remove a rule.

Syntax

[no] {permit | deny}

{any | host source-ipv6-address | source-ipv6-address[/prefix-lengLth]}
{any | destination-ipv6-address[/prefix-length]} [dscp dscp]

any – Any IP address (an abbreviation for the IPv6 prefix ::/0).
host – Keyword followed by a specific source IP address.
source-ipv6-address - An IPv6 source address or network class. The

address must be formatted according to RFC 2373 “IPv6 Addressing
Architecture,” using 8 colon-separated 16-bit hexadecimal values. One
double colon may be used in the address to indicate the appropriate
number of zeros required to fill the undefined fields.

destination-ipv6-address - An IPv6 destination address or network class.

The address must be formatted according to RFC 2373 “IPv6 Addressing
Architecture,” using 8 colon-separated 16-bit hexadecimal values. One
double colon may be used in the address to indicate the appropriate
number of zeros required to fill the undefined fields. (The switch only checks
the first 64 bits of the destination address.)

prefix-length - A decimal value indicating how many contiguous bits (from

the left) of the address comprise the prefix; i.e., the network portion of the
address. (Range: 0-128 for source prefix, 0-8 for destination prefix)

dscp – DSCP traffic class. (Range: 0-63)

Default Setting

None

Command Mode

Extended IPv6 ACL

Command Usage

All new rules are appended to the end of the list.

Example
This example accepts any incoming packets if the destination address is
2009:DB9:2229::79/8.

This allows packets to any destination address when the DSCP value is 5.

Console(config-ext-ipv6-acl)#permit 2009:DB9:2229::79/8
Console(config-ext-ipv6-acl)#

Console(config-ext-ipv6-acl)#permit any dscp 5
Console(config-ext-ipv6-acl)#