C613-50631-01 Rev A Command Reference for IE340 Series 2069
AlliedWare Plus™ Operating System - Version 5.5.3-0.x
IPV6 HARDWARE ACCESS CONTROL LIST (ACL) COMMANDS
(NAMED IPV6 HARDWARE ACL: IP PROTOCOL ENTRY)
(named IPv6 hardware ACL: IP protocol
entry)
Overview Use this command to add an IP protocol type filter entry to the current IPv6
hardware access-list. The filter will match on IPv6 packets that have the specified
IP protocol number, and the specified IPv6 addresses. You can use the value any
instead of source or destination IPv6 address if an address does not matter.
The no variant of this command removes a filter entry from the current hardware
access-list. You can specify the filter entry for removal by entering either its
sequence number (e.g. no 100), or by entering its filter profile without specifying
its sequence number (e.g. no deny proto 2 2001:0db8::0/64 any).
You can find the sequence number by running the show ipv6 access-list (IPv6
Hardware ACLs) command.
Hardware ACLs will permit access unless explicitly denied by an ACL action.
CAUTION: Specifying a “send” action enables you to use ACLs to redirect packets from
their original destination. Use such ACLs with caution. They could prevent control
packets from reaching the correct destination, such as EPSR healthcheck messages
and AMF messages.
Syntax
[<sequence-number>] <action> proto <1-255> <source-addr>
<dest-addr> [vlan <1-4094>]
no <sequence-number>
no <action> proto <1-255> <source-addr> <dest-addr> [vlan
<1-4094>]
The following actions are available for hardware ACLs:
Values for the <action> parameter
deny Reject packets that match the source and destination
filtering specified with this command.
permit Permit packets that match the source and destination
filtering specified with this command.
copy-to-cpu Send a copy of matching packets to the CPU.
copy-to-mirror Send a copy of matching packets to the mirror port.
Use the mirror interface command to configure the mirror
port.
send-to-mirror Send matching packets to the mirror port.
Use the mirror interface command to configure the mirror
port.
send-to-vlan-port
vlan <vid> port
<port-number>
Send matching packets to the specified port, tagged with
the specified VLAN. The specified port must belong to the
specified VLAN.
send-to-cpu Send matching packets to the CPU.