ZXR10ZSRV2CongurationGuide(IPv6)
CommandFunction
ZXR10(config)#showrunning-configport-acl[
all][|{begin|exclude|include}<key_words>]
DisplaysalltheIPv6ACLbinding
information(andtheIPv4ACLbinding
informationaswellasifanyIPv4ACL
isbound).
–EndofSteps–
20.3IPv6ACLCongurationExample
CongurationDescription
InthenetworkasshowninFigure20-1,supposebothPC1andPC2sendtelnetrequests
throughR2toR1.R1expectstoreceivetheloginrequestsofPC1onlybutnotthelogin
requestsofPC2.ThenanACLcanbeboundtotheingressdirectionoftheinterface
gei-1/3tolteroutthetelnetpacketsfromPC2(ortheACLmaybebindedtotheegress
directionoftheinterfacegei-1/4).
Figure20-1IPv6ACLCongurationExample
Inthiscase,itisonlynecessarytocreateoneACLandaddthefollowingruletothisACL:
DenythetelnetpacketsmatchingtheIPaddressofPC2andusingtheprotocoltypeTCP
andtheporttypetelnet.ThenbindtheACLtotheingressdirectionoftheinterfacegei-1/3
ortheegressdirectionoftheinterfacegei-1/4.
Aftertheabovecongurationiscompleted,therequestsinitiatedbyPC2donotreachR1
butarediscardedwhentheyreachR2evenifPC2hasnotobtainedthetelnetusername
andpasswordofR1.TheothercommunicationsofR1andPC2,however,arenotbe
affected.
CongurationFlow
1.EnableIPv6andconguretheinterfaceaddressesonrouters.
2.Firstcreateanipv6-access-list.Duringthecreation,acustomizednamecanbe
assignedtothislistbutthelengthofthenameshallnotexceed31characters.
20-4
SJ-20140504150128-018|2014-05-10(R1.0)ZTEProprietaryandCondential