ZXR108900SeriesUserManual(BasicCongurationVolume)
ExampleThisexampledescribeshowtocongureahybridACL.Itisre-
quiredtoimplementthefollowingfunctions:
�PermitaccessofUDPmessagesfromnetwork210.168.1.0/24,
destinationIPaddress210.168.2.10,destinationMACaddress
00d0.d0c0.5741,sourceport100anddestinationport200.
�DeniesBGPmessagesfromnetwork192.168.3.0/24.
�DeniesmessagesfromMACaddress0100.2563.1425.
ZXR10(config)#aclhybridnumber300
ZXR10(config-hybd-acl)#rule1permitudp210.168.1.00.0.0.255Eq
00210.168.2.100.0.0.0eq200Egress00d0.d0c0.57410000.0000.0000
ZXR10(config-hybd-acl)#rule2denytcp192.168.3.0.0.0.255
qBGPany
ZXR10(config-hybd-acl)#ruledenyanyany
ngress0100.2563.14250000.0000.0000
DefiningStandardIPv6ACL
TocongurestandardIPv6ACL,performthefollowingsteps.
Step
CommandFunction
1
ZXR10(config)#ipv6aclstandard{number
<acl-number>|name<acl-name>|alias
<alias-name>}[match-order{auto|config}]
ThisentersstandardIPv6ACL
congurationmode
2
ZXR10(config-std-v6acl)#rule<rule-no>{permit|den
y}{<source>|any}[time-range<timerange-name>]
ThisdenesACLrule
3
ZXR10(config-std-v6acl)#move<rule-no>{after|
before}<rule-no>
Thismovesarule
4
ZXR10(config-std-v6acl)#attachtime-range<Te
rangename>to<ruleid>
Thisbindsatimerangetoa
rule
ExampleThisexampleshowshowtocongurestandardIPv6ACL.Itdenes
anACLthatallowspacketsfromnetworksegment3001::/16to
pass.
ZXR10(config)#ipv6aclstandardnumber2000
ZXR10(config-std-v6acl)#rule1permit3001::/16
DefiningExtendedIPv6ACL
TocongureextendedIPv6ACL,performthefollowingsteps.
Step
CommandFunction
1
ZXR10(config)#ipv6aclextended{number
<acl-number>|name<acl-name>|alias
<alias-name>}[match-order{auto|config}]
ThisentersextendedIPv6
ACLcongurationmode
2
ZXR10(config-ext-v6acl)#rule<rule-no>{permit|de
ny}ip{<source>|any}{<dest>|any}[time-range
<timerange-name>]
ThisdenesACLrule
82CondentialandProprietaryInformationofZTECORPORATION