HP 6125G HP 6125G & 6125G/XG Blade Switches ACL and QoS Configuration - Page 11

Configuring an IPv6 basic ACL

Page 11 highlights

Step Command 1. Enter system view. system-view Remarks N/A 2. Create an IPv4 basic ACL and enter its view. acl number acl-number [ name acl-name ] [ match-order { auto | config } ] 3. Configure a description for the description text IPv4 basic ACL. By default, no ACL exists. IPv4 basic ACLs are numbered in the range of 2000 to 2999. You can use the acl name acl-name command to enter the view of a named IPv4 ACL. Optional. By default, an IPv4 basic ACL has no ACL description. 4. Set the rule numbering step. step step-value Optional. The default setting is 5. 5. Create or edit a rule. rule [ rule-id ] { deny | permit } [ counting | fragment | source { sour-addr sour-wildcard | any } | time-range time-range-name | vpn-instance vpn-instance-name ] * By default, an IPv4 basic ACL does not contain any rule. If the ACL is for QoS traffic classification or packet filtering, do not specify the vpn-instance keyword. This keyword can cause ACL application failure. The counting keyword (even if specified) does not take effect for QoS policies. 6. Add or edit a rule comment. rule rule-id comment text Optional. By default, no rule comments are configured. 7. Add or edit a rule Optional. range remark. rule [ rule-id ] remark text By default, no rule range remarks are configured. 8. Enable counting ACL rule matches performed in hardware-count enable hardware. Optional. Disabled by default. When the ACL is referenced by a QoS policy, this command does not take effect. Configuring an IPv6 basic ACL Step 1. Enter system view. 2. Create an IPv6 basic ACL view and enter its view. 3. Configure a description for the IPv6 basic ACL. 4. Set the rule numbering step. Command Remarks system-view N/A acl ipv6 number acl6-number [ name acl6-name ] [ match-order { auto | config } ] By default, no ACL exists. IPv6 basic ACLs are numbered in the range of 2000 to 2999. You can use the acl ipv6 name acl6-name command to enter the view of a named IPv6 ACL. description text Optional. By default, an IPv6 basic ACL has no ACL description. step step-value Optional. The default setting is 5. 5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84

5
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an IPv4
basic ACL and
enter its view.
acl number
acl-number
[
name
acl-name
]
[
match-order
{
auto
|
config
} ]
By default, no ACL exists.
IPv4 basic ACLs are numbered in the range of 2000 to
2999.
You can use the
acl
name
acl-name
command to enter
the view of a named IPv4 ACL.
3.
Configure a
description for the
IPv4 basic ACL.
description
text
Optional.
By default, an IPv4 basic ACL has no ACL description.
4.
Set the rule
numbering step.
step
step-value
Optional.
The default setting is 5.
5.
Create or edit a
rule.
rule
[
rule-id
] {
deny
|
permit
} [
counting
|
fragment
|
source
{
sour-addr sour-wildcard
|
any
} |
time-range
time-range-name
|
vpn-instance
vpn-instance-name
] *
By default, an IPv4 basic ACL does not contain any rule.
If the ACL is for QoS traffic classification or packet
filtering, do not specify the
vpn-instance
keyword. This
keyword can cause ACL application failure. The
counting
keyword (even if specified) does not take effect
for QoS policies.
6.
Add or edit a rule
comment.
rule
rule-id
comment
text
Optional.
By default, no rule comments are configured.
7.
Add or edit a rule
range remark.
rule
[
rule-id
]
remark
text
Optional.
By default, no rule range remarks are configured.
8.
Enable counting
ACL rule matches
performed in
hardware.
hardware-count enable
Optional.
Disabled by default.
When the ACL is referenced by a QoS policy, this
command does not take effect.
Configuring an IPv6 basic ACL
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an IPv6
basic ACL view
and enter its view.
acl ipv6 number
acl6-number
[
name
acl6-name
]
[
match-order
{
auto
|
config
} ]
By default, no ACL exists.
IPv6 basic ACLs are numbered in the range of 2000
to 2999.
You can use the
acl
ipv6
name
acl6-name
command
to enter the view of a named IPv6 ACL.
3.
Configure a
description for the
IPv6 basic ACL.
description
text
Optional.
By default, an IPv6 basic ACL has no ACL
description.
4.
Set the rule
numbering step.
step
step-value
Optional.
The default setting is 5.