Chapter20IPv6ACLConguration
3.EntertheIPv6ACLcongurationmodeafterthelistiscreatedandthenaddrules.A
packettypecanbespeciedforeachrule,andthepermitordenyactionappliesto
thepackettype.
4.Bindthecustomizedipv6-access-listtotheingressoregressdirectionoftheinterface
towhichtrafclteringapplies.
CongurationCommands
Thisexampledoesnotcovertheinterfaceaddressconguration,andisomittedinthis
example.
CongurationonR2:
R2(config)#ipv6-access-listtest
R2(config-ipv6-acl)#ruledenytcp100:1::1:2/128eq23110:1::1:2/128
R2(config-ipv6-acl)#rulepermitipanyany
R2(config-ipv6-acl)#exit
R2(config)#ipv6-access-groupinterfacegei-1/3ingresstest
CongurationVerication
ChecktheconguredACLinoneofthefollowingthreemodes,asshownbelow.
/*CheckalltheACLsontherouter.Inthismode,allthenames
andnumberofACLsareshown*/
R2(config)#showipv6-access-listsbrief
No.ACLRuleSum
-------------------------------------------------------
1test2
/*ChecktheACLofthespecifiedname.Inthismode,information
aboutthenumberofrulesofthespecifiedACLisshown.*/
R2(config)#showipv6-access-listsnametest
ipv6-access-listtest
2/2(showed/total)
10denytcp100:1::1:2/128eqtelnet110:1::1:2/128
20permitipanyany
/*CheckthedetailsofallACLsontherouter.Inthismode,
informationaboutthenumberofrulesofeachACLisshown.*/
R2(config)#showipv6-access-lists
ipv6-access-listtest
2/2(showed/total)
10denytcp100:1::1:2/128eqtelnet110:1::1:2/128
20permitipv6anyany
ChecktheinterfaceboundwiththeACL.Twomethodsareavailableforcheckingthe
bindingbetweentheACLandtheinterface,asshownbelow.
20-5
SJ-20140504150128-018|2014-05-10(R1.0)ZTEProprietaryandCondential