Chapter20
IPv6ACLConguration
TableofContents
IPv6ACLOverview..................................................................................................20-1
ConguringIPv6ACL...............................................................................................
20-1
IPv6ACLCongurationExample.............................................................................20-4
20.1IPv6ACLOverview
TheAccessControlList(ACL)isakindofowclassicationpolicyusedtoimplement
numerousfunctionssuchasport-ACL,UnicastReversePathForwarding(URPF)and
policyrouting.
TheIPv6ACLmechanismisusedtolterpacketsbytheeldsinIPv6packets.
OneIPv6ACLcanhavemultiplerules,witheachruledescribingcertainmatching
conditions.Foragivenpacket,matchingstartsfromtherstrule.Onceapacketmatches
acertainrule,thepermitordenyactionsetintheruleisreturned.
20.2ConguringIPv6ACL
ThisproceduredescribeshowtocongureanIPv6ACLrulepolicy.
Steps
1.EnterIPv6ACLcongurationmodeandconguretheIPv6ACLrule.
StepCommandFunction
1ZXR10(config)#ipv6-access-list<acl-name>ConguresthespeciedIPv6
ACL.
ZXR10(config-ipv6-acl)#rule[<rule-id>]{permit
|deny}[flowlabel<flowlabel-value>]{<0-255>|
ipv6|<protocol-type>}{[<source-ipv6-address>|
any}{<destination-ipv6-address>|any}[dscp
<dscp-value>][{[routing],[authen],[destopts],[fragme
nts],[hop-by-hop],[esp]}][time-range<time-range-name>]
CongurestheextendedIPv6
ACLrule.
ZXR10(config-ipv6-acl)#rule[<rule-id>]{permit|den
y}[flowlabel<flowlabel-value>]tcp{<source-ipv6-address>|
any}[{<operator>{<0-65535>|<source-porttype>}|range
<0-65535>-<0-65535>}]{<destination-ipv6-address>|
any}[{<operator>{<0-65535>|<destination-porttype>}|
CongurestheIPv6ACLrule
basedonTCP.
2
20-1
SJ-20140504150128-018|2014-05-10(R1.0)ZTEProprietaryandCondential