Qtech QSW-8200-28T-POEAC- DC [23/114] Permit deny ipv6 extended

Qtech QSW-8200-28T-AC [23/114] Permit deny ipv6 extended
User Manual
Chapter 1. Commands for ACL 23
www.qtech.ru
Command Mode: Name standard IP access-list configuration mode
Default: No access-list configured.
Example: Permit packets with source address 10.1.1.0/24 to pass, and deny other
packets with source address 10.1.1.0/16.
Switch(config)# access-list ip standard ipFlow
Switch(Config-Std-Nacl-ipFlow)# permit 10.1.1.0 0.0.0.255
Switch(Config-Std-Nacl-ipFlow)# deny 10.1.1.0 0.0.255.255
1.23 permit | deny(ipv6 extended)
Command: [no] {deny | permit} icmp {{<sIPv6Prefix/sPrefixlen>} | any-source | {host-
source <sIPv6Addr>}} {<dIPv6Prefix/dPrefixlen> | any-destination | {host-destination
<dIPv6Addr>}} [<icmp-type> [<icmp-code>]] [dscp <dscp>] [flow-label <fl>][time-range
<time-range-name>]
o [no] {deny | permit} tcp { <sIPv6Prefix/sPrefixlen> | any-source | {host-source
<sIPv6Addr> }} [s-port { <sPort> | range <sPortMin> <sPortMax> }] {
<dIPv6Prefix/dPrefixlen> | any-destination | {host-destination <dIPv6Addr> }}
[d-port { <dPort> | range <dPortMin> <dPortMax> }] [syn | ack | urg | rst | fin
| psh] [dscp <dscp> ] [flow-label <fl> ][time-range <time-range-name> ]
o [no] {deny | permit} udp { <sIPv6Prefix/sPrefixlen> | any-source | {host-source
<sIPv6Addr> }} [s-port { <sPort> | range <sPortMin> <sPortMax> }] {
<dIPv6Prefix/dPrefixlen> | any-destination | {host-destination <dIPv6Addr> }}
[d-port { <dPort> | range <dPortMin> <dPortMax> }] [dscp <dscp> ] [flow-label
<fl> ][time-range <time-range-name> ]
o [no] {deny | permit} <next-header> {<sIPv6Prefix/sPrefixlen> | any-source |
{host-source <sIPv6Addr>}} {<dIPv6Prefix/dPrefixlen> | any-destination |
{host-destination <dIPv6Addr>}} [dscp <dscp>] [flow-label <fl>][time-range
<time-range-name>]
o [no] {deny | permit} {<sIPv6Prefix/sPrefixlen> | any-source | {host-source
<sIPv6Addr>}} {<dIPv6Prefix/dPrefixlen> | any-destination | {host-destination
<dIPv6Addr>}} [dscp <dscp>] [flow-label <fl>] [time-range<time-range-name>]
Function: Create an extended nomenclature IPv6 access control rule for specific IPv6
protocol.
Parameter: <sIPv6Addr> is the source IPv6 address; <sPrefixlen> is the length of the
IPv6 address prefix, the range is 1128; <dIPv6Addr> is the destination IPv6 address;
<dPrefixlen> is the length of the IPv6 address prefix, the range is 1128; <igmp-type>,
type of the IGMP; <icmp-type>, icmp type; <icmp-code>, icmp protocol number;
<dscp>, IPv6 priority ,the range is 063; <flowlabel>, value of the flow label, the range
is 01048575; syn,ack,urg,rst,fin,psh,tcp label position; <sPort>, source port number,
the range is 065535; <sPortMin>, the down boundary of source port; <sPortMax>,
the up boundary of source port; <dPort>, destination port number, the range is 0
65535; <dPortMin>, the down boundary of destination port; <dPortMax>, the up

Содержание

Похожие устройства

Скачать