Security
104
System Management Guide
3HE 11018 AAAC TQZZA Edition: 01
match
Syntax match [next-header next-header]
no match
Context config>system>security>cpm-filter>ipv6-filter>entry
Description This command enables the context to enter match criteria for the IPv6 filter entry. When the
match criteria have been satisfied, the action associated with the match criteria is executed.
If more than one match criterion (within one match statement) is configured, all criteria must
be satisfied (AND function) before the action associated with the match is executed.
A match context may consist of multiple match criteria, but multiple match statements cannot
be entered per entry.
The no form of the command removes the match criteria for the entry-id.
Parameters next-header — protocol-number or protocol-name
protocol-number — the IPv6 next header to match, expressed as a protocol number in
decimal, hexadecimal, or binary. This parameter is similar to the protocol parameter
used in IPv4 filter match criteria. See Table 6 for the protocol IDs and descriptions for
the IP protocols.
Values [1 to 42 | 45 to 49 | 52 to 59 | 61 to 255]D
[0x0..0x2A | 0x2D..0x31 | 0x34..0x3B | 0x3D..0xFF]H
103 pim Protocol Independent Multicast
112 vrrp Virtual Router Redundancy Protocol
115 l2tp Layer Two Tunneling Protocol
118 stp Schedule Transfer Protocol
123 ptp Performance Transparency Protocol
124 isis ISIS over IPv4
126 crtp Combat Radio Transport Protocol
127 crudp Combat Radio User Datagram
132 sctp Stream Control Transmission Protocol
137 mpls-in-ip MPLS in IP
Table 6 IP Protocol IDs and Descriptions (Continued)
Protocol ID Protocol Description