Chapter9ACLConguration
Step
CommandFunction
3
ZXR10(config-ext-v6acl)#move<rule-no>{after|
before}<rule-no>
Thismovesarule
4
ZXR10(config-ext-v6acl)#attachtime-range<Time
rangename>to<ruleid>
Thisbindsatimerangetoa
rule
ExampleThisexampleshowshowtocongureextendedIPv6ACL.Itde-
nesanACLthatallowspacketsfromnetworksegment3000::/16
to4000::/16topass.
ZXR10(config)#ipv6aclextended2500
ZXR10(config-ext-v6acl)#rule1permit3000::/164000::/16
DefiningCustomizedACL
TocongurecustomizedACL,performthefollowingsteps.
Step
CommandFunction
1
ZXR10(config)#acluser-defined{number
<3000-3499>|name<acl-name>|alias<
alias-name>}
ThisentersbasicACL
congurationmode
2
ZXR10(config-user-acl)#rule<rule-id>{permit
|deny}{any|{tag<tag-num><offset><rule-
string><rule-mask>&<1-4>}}[time-range<
timerange-name>]
ThisdenesACLrule
3
ZXR10(config-user-acl)#move<rule-no>{after|
before}<rule-no>
Thismovesarule
4
ZXR10(config-user-acl)#attachtime-range<Time
rangename>to<ruleid>
Thisbindsatimerangetoa
rule
ExampleThisexampleshowshowtocongureextendedIPv6ACL.
AuserdenesanACLtoallowpacketswiththefollowingfeatures
topass:
�Tagis1.
�Ruleis0x1111.
�Maskis0x000f.
�Offsetis4bytes.
ZXR10(config)#acluser-definenumber3000
ZXR10(config-user-acl)#rule1permittag140x11110x000f
ConfiguringTimeRange
Toconguretimerange,performthefollowingsteps.
CondentialandProprietaryInformationofZTECORPORATION83