ACL Commands
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide 56
2
switchxxxxxx(config-ip-al)#
permit
tcp
2001:0DB8:0300:0201::/64
any
any
80
2.5 permit ( IPv6 )
Use the permit command in Ipv6 Access-list Configuration mode to set permit
conditions (ACEs) for IPv6 ACLs. Use the no form of the command to remove the
access control entry.
Syntax
permit
protocol
{any |{
source-prefix
/
length
}{any |
destination-prefix
/
length
}
[ace-priority
priority
][dscp
number
| precedence
number
]
[time-range
time-range-name
]
[log-input]
permit icmp
{any | {
source-prefix
/
length
}{any |
destination-prefix
/
length
}
{any|
icmp-type
} {any|
icmp-code
}
[ace-priority
priority
][dscp
number
| precedence
number
]
[time-range
time-range-name
]
[log-input]
permit tcp
{any | {
source-prefix
/
length
} {any |
source-port
/
port-range
}}{any |
destination-prefix
/
length
} {any|
destination-port
/
port-range
}
[ace-priority
priority
][dscp
number
| precedence
number
] [match-all
list-of-flags
]
[time-range
time-range-name
]
[log-input]
permit
udp
{any | {
source-prefix
/
length
}} {any |
source-port
/
port-range
}}{any |
destination-prefix
/
length
} {any |
destination-port
/
port-range
}
[ace-priority
priority
][dscp
number
| precedence
number
][time-range
time-range-name
]
[log-input]
no permit
protocol
{any |{
source-prefix
/
length
}{any |
destination-prefix
/
length
}
[dscp
number
| precedence
number
]
[time-range
time-range-name
]
[log-input]
no permit icmp
{any | {
source-prefix
/
length
}{any |
destination-prefix
/l
ength
}
{any|
icmp-type
} {any|
icmp-code
} [dscp
number
| precedence
number
]
[time-range
time-range-name
]
[log-input]
no permit tcp
{any | {
source-prefix
/
length
} {any | source-port/port-range}}{any |
destination- prefix/length} {any|
destination-port
/
port-range
} [dscp
number
|
precedence
number
] [match-all
list-of-flags
]
[time-range
time-range-name
]
[log-input]
no permit udp {any | {
source-prefix
/
length
}} {any |
source-port
/
port-range
}}{any |
destination-prefix
/
length
} {any|
destination-port
/
port-range
} [dscp
number
|
precedence
number
]
[time-range
time-range-name
]
[log-input]