Chapter2ACLConguration
Syntax
Description
<protocol>Protocoltypetobematched,ICMP ,IP ,TCPor
UDP;anintegerstandingfortheIPprotocol
number ,range:0~254
<source/prefix>IPaddress/prexlengthofthesourcetobe
matched,inhexadecimalformat
<destination/prefix>IPaddress/prexlengthofthedestinationto
bematched,inhexadecimalformat
time-range
<timerange-name>
Timerangename,thelengthisnotmorethan
31characters
ExampleThisexampledescribeshowtopermittheaccesstothehoston
thespeciednetwork.
ZXR10(config)#ipv6aclextendednumber100
ZXR10(config-ext-v6acl)#permitipany105A:1002::1000/100
ZXR10(config-ext-v6acl)#permitip1030::1000/90102A:A002::1000/100
Related
Commands
deny
rule(BasicACL)
PurposeUsethiscommandtodeneabasicACLrule.Removetherule
withthenoformofthiscommand.
CommandModesBasicACLconguration
Syntaxrule<rule-no>{permit|deny}{<source>[<source-wil
dcard>]|any}[{time-range<timerange-name>|event
<event-name>}]
norule<rule-no>
Syntax
Description
<rule-no>ACLrulenumber ,range:~00(switch),
1~1000(router)
permitPermitsthepacketthatmatchesthisrule
denyDeniesthepacketthatmatchesthisrule
<source>
SourceIPaddress
<source-wildcard>
WildcardmaskofthesourceIPaddress
any
AnysourceIPaddress
time-range
<timerange-name>
Timesegmentname,notmorethan31
characters
event<event-name>
Eventlistname,notmorethan31characters
InstructionsIfthetime-rangeeldisnotcongured,thisrulewillbeeffective
permanently.Therelevanttimerangecommandmustbecong-
uredbeforetheuseofthetime-rangeeld.
CondentialandProprietaryInformationofZTECORPORATION25