D-Link DGS-6608 — руководство по настройке IPv6 расширенных списков доступа [558/1106]

Превью страниц Страница 558 / 1106
D-Link DGS-6608 [558/1106] Command mode
DGS-6600 Series Switch m permit | deny (ipv6 access list)
CLI Reference Guide
548
Default None.
Command Mode IPv6 extended access list configuration.
Usage Guideline The time range profile needs to be created before it can be specified in the
statement. Otherwise an error message will be displayed.
All the configurable arguments (time-range and priority are excluded) can be
used to differentiate one from another. These arguments are called differentiated
arguments. To remove an entry, in the no form of this command, specify the entry
with the same value of all differentiating arguments specified prior (includes all
optional parameters but the time-range and priority are excluded).
To update the time-range or priority, specify the entry with the same value of all
differentiating arguments, which are configured, and the update value for time-
range or priority.
The priority value must be unique in the domain of an access list. If a priority
value entered is already present, an error message will be shown.
Example This example shows create three entries for an IPv6 extended access list,
named "ipv6-control". The three entries are: permit TCP packets destined to
network ff02::0:2/16, permit TCP packets destined to host ff02::1:2 and permit all
ICMPv6 packets.
Verify the settings by entering the show access-list command.
PROFILE-NAME Used with the no form of the commands, this option, time-range (without
PROFILE-NAME), means to remove the setting of an active timer-period,
rather than remove the whole entry.
PRIORITY The range is 1 to 65535. The lower the number represents a better priority. It
is used as the rule sequence number.
Syntax Description
Switch(config)#ipv6 access-list extended ipv6-control
The maximum available of IPv6 extended access-list is 255
Switch(config-ipv6-ext-acl)#permit tcp any ff02::0:2 ffff::
Switch(config-ipv6-ext-acl)#permit tcp any host ff02::1:2
Switch(config-ipv6-ext-acl)#permit icmpv6 any any

Содержание

4839

Изучите, как настраивать и управлять IPv6 расширенными списками доступа, включая команды для разрешения и запрета трафика. Подробные примеры и советы.