Yamaha 10G SWR2310-28GT/18GT/10G Command Reference - Page 231

Generate IPv6 access list

Page 231 highlights

Command Reference | Traffic control | 231 If the received/transmitted frame matches the conditions in the access list, the action in the access list will be the action (permit, deny) for the corresponding frame. If this command is executed with the "no" syntax, the applied access list is deleted from both LAN/SFP port and logical interface. [Note] Only one access list for each direction can be registered for incoming frames (in) and for outgoing frames (out) on the same interface. The access list for transmitted frames can only be applied to LAN/SFP port. The following restrictions apply. An IPv4 access list for which the port number range (range X Y) is specified cannot be applied to transmitted frames (out). An LAN/SFP port for which an incoming frames access list is specified cannot be associated to an logical interface. An incoming frames access list cannot be applied to an LAN/SFP port that is associated with an logical interface. However, if an access list setting for incoming frames is specified for an LAN/SFP port that is associated with an logical interface in the startup config, then the setting for the lowest-numbered port is applied to the logical interface. [Example] Apply extended IPv4 access list #1 to received frames of LAN port #1. SWR2310(config)#interface port1.1 SWR2310(config-if)#access-group 1 in 9.1.4 Generate IPv6 access list [Syntax] access-list ipv6-acl-id [seq_num] action src-info no access-list ipv6-acl-id [seq_num] [action src-info] [Parameter] ipv6-acl-id : ID of IPv6 access list seq_num : Sequence number. Specifies the position of the entry within the applicable access list. If the sequence number is omitted, the entry is added to the end of the list. At this time, the new entry is automatically given a number that is 10 greater than the last existing entry. (If an entry is initially added without a sequence number, its entry number will be 10.) action : Specifies the action for the access condition deny permit Setting value Description "Deny" the condition "Permit" the condition src-info : Specifies the transmission-source IPv6 address that is the condition X:X::X:X/M any Setting value Description Specifies an IPv6 address (X:X::X:X) with subnet mask length (Mbit) Applies to all IPv6 addresses [Initial value] none [Input mode] global configuration mode [Description] Generates an IPv6 access list. Multiple conditions (maximum 256) can be specified for the generated access list.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278

If the received/transmitted frame matches the conditions in the access list, the action in the access list will be the action (permit,
deny) for the corresponding frame.
If this command is executed with the "no" syntax, the applied access list is deleted from both LAN/SFP port and logical
interface.
[Note]
Only one access list for each direction can be registered for incoming frames (in) and for outgoing frames (out) on the same
interface.
The access list for transmitted frames can only be applied to LAN/SFP port.
The following restrictions apply.
An IPv4 access list for which the port number range (range X Y) is specified cannot be applied to transmitted frames (out).
An LAN/SFP port for which an incoming frames access list is specified cannot be associated to an logical interface.
An incoming frames access list cannot be applied to an LAN/SFP port that is associated with an logical interface. However, if
an access list setting for incoming frames is specified for an LAN/SFP port that is associated with an logical interface in the
startup config, then the setting for the lowest-numbered port is applied to the logical interface.
[Example]
Apply extended IPv4 access list #1 to received frames of LAN port #1.
SWR2310(config)#interface port1.1
SWR2310(config-if)#access-group 1 in
9.1.4 Generate IPv6 access list
[Syntax]
access-list
ipv6-acl-id
[
seq_num
]
action
src-info
no
access-list
ipv6-acl-id
[
seq_num
] [
action
src-info
]
[Parameter]
ipv6-acl-id
:
<3001-4000>
ID of IPv6 access list
seq_num
:
<1-65535>
Sequence number. Specifies the position of the entry within the applicable access list.
If the sequence number is omitted, the entry is added to the end of the list. At this time, the new entry
is automatically given a number that is 10 greater than the last existing entry. (If an entry is initially
added without a sequence number, its entry number will be 10.)
action
:
Specifies the action for the access condition
Setting value
Description
deny
"Deny" the condition
permit
"Permit" the condition
src-info
:
Specifies the transmission-source IPv6 address that is the condition
Setting value
Description
X:X::X:X/M
Specifies an IPv6 address (X:X::X:X) with
subnet mask length (Mbit)
any
Applies to all IPv6 addresses
[Initial value]
none
[Input mode]
global configuration mode
[Description]
Generates an IPv6 access list.
Multiple conditions (maximum 256) can be specified for the generated access list.
Command Reference | Traffic control |
231