ZXR105900/5200SeriesUserManual(BasicCongurationVolume)
ConfiguringBasicIPV6ACL
Step
CommandFunction
1
ZXR10(config)#ipv6aclstandard{number
<acl-number>|name<acl-name>}
ThisentersthebasicACL
congurationmode.
2
ZXR10(config-std-v6acl)#rule<1-100>{permit|de
ny}{<source>|any}[mac(<Source-mac><Source
wildcardbits>)][time-range<timerange-name>]
Thiscongurestherulesof
ACL.
3
ZXR10(config-std-v6acl)#move<rule-no>{after|
before}<rule-no>
Thismovesarulebehind
anotherrule.
ExampleInthisexample,deneaACLtopermitIPpacketswiththenetwork
segmentas10.0.0.0.0.0.0.0/16topass.
ZXR10(config)#ipv6aclstandardnumber2000
ZXR10(config-std-v6acl)#rule1permit10::/16
ConfiguringExtendedIPV6ACL
Step
CommandFunction
1
ZXR10(config)#ipv6aclextended{number
<acl-number>|name<acl-name>}
ThisentersACLconguration
mode.
2
ZXR10(config-ext-v6acl)#rule<1-maxRuleNo
>{permit|deny}{(icmp{<source/prefix>|
any}{<destination/prefix>|any})|(<protocol
>{<source/prefix>|any}{<destination/prefix>|
any})|(tcp{<source/prefix>|any}[<rule>{<0-m
axPortNo>|<tcpporttype>}]{<destination/prefix>|
any}[<rule>{<0-maxPortNo>|<tcpporttype>}])
|(udp{<source/prefix>|any}[<rule>{<0-max
PortNo>|<udpporttype>}]{<destination/prefix>|
any}[<rule>{<0-maxPortNo>|<udpporttype>}])
}[ingress(<Sourcemacaddress><Source
wildcardbits>)][egress(<Destinationmac
address><Destinationwildcardbits>)][{time-range
<timerange-name>|event<event-name>}]
Thiscongurestherulesof
ACL.
3
ZXR10(config-ext-v6acl)#move<rule-no>{after|
before}<rule-no>
Thismovesarulebehind
anotherrule.
ExampleInthisexample,deneaextendedipv6ACLtopermitIPpackets
withthesourceipnetworksegmentas10.0.0.0.0.0.0.0/16and
destinationipnetworksegmentas20.0.0.0.0.0.0.0/16topassand
denythepacketswithMACaddress0012.0001.0002topass.
ZXR10(config)#ipv6aclextended2500
ZXR10(config-ext-v6acl)#rule1permit10::/1620::/16
ZXR10(config-ext-v6acl)#rule2denyfragmentanyanyingress0012
0001.00020000.0000.0000
64CondentialandProprietaryInformationofZTECORPORATION