beautypg.com

Allied Telesis AT-S95 CLI (AT-8000GS Series) User Manual

Page 33

background image

ACL Commands

Page 33

Parameters

destination-port — Specifies the UDP/TCP destination port. (Range: 0 - 65535)

destination-prefix/length — The destination IPv6 network or class of networks about which to set permit

conditions. This argument must be in the form documented in RFC 3513, where the address is specified in
hexadecimal using 16-bit values between colons.

disable-port — The Ethernet interface would be disabled if the condition is matched.

dscp number — Matches a differentiated services codepoint value against the traffic class value in the Traffic

Class field of each IPv6 packet header. (Range: 0 - 63)

flags list-of-flags — List of TCP flags that should occur. If a flag should be set, it is prefixed by +. If a flag

should be unset, it is prefixed by -. Avaiable options are +urg, +ack, +psh, +rst, +syn, +fin, -urg, -ack, -psh,
-rst, -syn and -fin. The flags are concatenated to one string. For example: +fin-ack.

icmp-type — Specifies an ICMP message type for filtering ICMP packets. Enter a number or one of the

following values: destination-unreachable, packet-too-big, time-exceeded, parameter-problem,
echo-request, echo-reply, mld-query, mld-report, mldv2-report, mld-done, router-solicitation,
router-advertisement, nd-ns, nd-na. (Range: 0 - 255)

icmp-code — Specifies an ICMP message code for filtering ICMP packets. (Range: 0 - 255)

ip-precedence number — Specifies the IP precedence value.

protocol — The name or the number of an IP protocol. Available protocol names are: icmp, tcp and udp.

(Range: 0 - 255)

destination-port — Specifies the UDP/TCP destination port. (Range: 1 - 65535)

source-port — Specifies the UDP/TCP source port. (Range: 1 - 65535)

source-prefix/length — The source IPv6 network or class of networks about which to set permit conditions.

This argument must be in the form documented in RFC 3513, where the address is specified in hexadecimal
using 16-bit values between colons.

Default Configuration

No IPv6 access list is defined.

Command Mode

IPv6 access list configuration

I P P r o t o c o l

A b b r e v i a t e d N a m e

P r o t o c o l N u m b e r

Transmission Control Protocol

tcp

6

User Datagram Protocol

udp

17

Internet Control Message Protocol

icmp

58

(any IP protocol)

any

25504