D-Link DGS-3130 Emulator - Page 60
permit | deny ipv6 access-list
View all D-Link DGS-3130 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 60 highlights
DGS-3130 Layer 3 Stackable Managed Switch CLI Reference Guide This example shows how to create two entries for an IP standard access list, named "std-acl". These entries are: permit IP packets destined for network 10.20.0.0, permit IP packets destined for host 10.100.1.2. Switch# configure terminal Switch(config)# ip access-list std-acl Switch(config-ip-acl)# permit any 10.20.0.0 0.0.255.255 Switch(config-ip- acl)# permit any host 10.100.1.2 Switch(config-ip- acl)# 4-16 permit | deny (ipv6 access-list) This command is used to add a permit entry or deny entry to the IPv6 access list. Use the no form of this command to remove an entry from the IPv6 access list. Extended IPv6 Access List: [SEQUENCE-NUMBER] {permit | deny} tcp {any | host SRC-IPV6-ADDR | SRC-IPV6-ADDR/PREFIXLENGTH} [{eq | lt | gt | neq} PORT | range MIN-PORT MAX-PORT] {any | host DST-IPV6-ADDR | DSTIPV6-ADDR/PREFIX-LENGTH} [{eq | lt | gt | neq} PORT | range MIN-PORT MAX-PORT | mask PORT MASK] [TCP-FLAG] [dscp VALUE | traffic-class VALUE] [flow-label FLOW-LABEL] [time-range PROFILENAME] [SEQUENCE-NUMBER] {permit | deny} udp {any | host SRC-IPV6-ADDR | SRC-IPV6-ADDR/PREFIXLENGTH} [{eq | lt | gt | neq} PORT | range MIN-PORT MAX-PORT] {any | host DST-IPV6-ADDR | DSTIPV6-ADDR/PREFIX-LENGTH} [{eq | lt | gt | neq} PORT | range MIN-PORT MAX-PORT] [dscp VALUE | traffic-class VALUE] [flow-label FLOW-LABEL] [time-range PROFILE-NAME] [SEQUENCE-NUMBER] {permit | deny} icmp {any | host SRC-IPV6-ADDR | SRC-IPV6-ADDR/PREFIXLENGTH} {any | host DST-IPV6-ADDR | DST-IPV6-ADDR/PREFIX-LENGTH} [ICMP-TYPE [ICMP-CODE] | ICMP-MESSAGE] [dscp VALUE | traffic-class VALUE] [flow-label FLOW-LABEL] [time-range PROFILENAME] [SEQUENCE-NUMBER] {permit | deny} {protocol-id PROTOCOL-ID} {any | host SRC-IPV6-ADDR | SRCIPV6-ADDR/PREFIX-LENGTH} {any | host DST-IPV6-ADDR | DST-IPV6-ADDR/PREFIX-LENGTH} [dscp VALUE | traffic-class VALUE]] [flow-label FLOW-LABEL] [time-range PROFILE-NAME] [SEQUENCE-NUMBER] {permit | deny} {any | host SRC-IPV6-ADDR | SRC-IPV6-ADDR/PREFIX-LENGTH} [any | host DST-IPV6-ADDR | DST-IPV6-ADDR/PREFIX-LENGTH] [fragments] [dscp VALUE | traffic-class VALUE] [flow-label FLOW-LABEL] [time-range PROFILE-NAME] Standard IPv6 Access List: [SEQUENCE-NUMBER] {permit | deny} {any | host SRC-IPV6-ADDR | SRC-IPV6-ADDR/PREFIX-LENGTH} [any | host DST-IPV6-ADDR | DST-IPV6-ADDR/PREFIX-LENGTH] [time-range PROFILE-NAME] no SEQUENCE-NUMBER Parameters SEQUENCE-NUMBER any host SRC-IPV6-ADDR SRC-IPV6-ADDR/PREFIXLENGTH host DST-IPV6-ADDR DST-IPV6-ADDR/PREFIXLENGTH Specifies the sequence number. The range is from 1 to 65535. The lower the number is, the higher the priority of the permit/deny rule. Specifies any source IPv6 address or any destination IPv6 address. Specifies a specific source host IPv6 address. Specifies a source IPv6 network. Specifies a specific destination host IPv6 address. Specifies a destination IPv6 network. 56