beautypg.com

13 ipv6 access-list, Access, List – PLANET XGS3-24040 User Manual

Page 738

background image

Commands for Security Function Chapter 2 Commands for 802.1x

41-10

41.13 ipv6 access-list

Command: ipv6 access-list {deny | permit} {> | any-source |

{host-source }}

ipv6 access-list {deny | permit} icmp {{ } |

any-source | {host-source }} { | any-destination |

{host-destination }} [ [ ]] [dscp ] [flow-label

][time-range ]

ipv6 access-list {deny | permit} tcp {{ } |

any-source | {host-source }} [s-port { | range }]

{{ } | any-destination | {host-destination }} [dPort

{ | range }] [syn | ack | urg | rst | fin | psh] [dscp ]

[flow-label ][time-range ]

ipv6 access-list {deny | permit} udp {{ } |

any-source | {host-source }} [s-port { | range }]

{{ } | any-destination | {host-destination }} [dPort

{ | range }] [dscp ] [flow-label ][time-range

]

ipv6 access-list {deny | permit} { |

any-source | {host-source }} { | any-destination |

{host-destination

}}

[dscp

]

[flow-label

][time-range

]

no ipv6 access-list { | }

Functions: Creates a numbered standard IP access-list, if the access-list already exists, then a rule will

add to the current access-list; the “no access-list {|} “command deletes a

numbered standard IP access-list.

Parameters: is the list number ,list range is between 500~599; is the list

number ,list range is between 600~699; is the prefix of the ipv6 source address;

is the length of prefix of the ipv6 source address, range is between 1~128;

is the ipv6 source address; is the prefix of the ipv6 destination address; > is

the length of prefix of the ipv6 destination address, range is between 1~128; is the ipv6

destination address; , the type of icmp; ,the protocol code of icmp;

IPv6 priority, range from 0 to 63; ,value of flow tag, range from 0 to 1048575; synack

urg

rst

fin

psh

tcp label position; , source port No., 0-65535; , the down boundary

of source port; , the up boundary of source port; ,destination port No., range from 0

to 65535; , the down boundary of destination port; , the up boundary of

destination port; ,the next header of IPv6, range from 0 to 255; , the

name of time-range.

Command Mode: Global Mode.

Default: No access-list configured.

Usage Guide: Creates a numbered 520 standard IP access-list first time, the following configuration will

add to the current access-list.

Examples: Creates a numbered 520 standard IP access-list, allow the source packet from

2003:1:2:3::1/64 pass through the net, and deny all the other packet from the source address