sequence (permit | deny in IPv6
ACLs)
Use the following syntax to define a TCP or UDP rule:
[sequence seq-num ] { deny | permit } { tcp | udp } { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } [ source-comparison-operators ] { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ established ] [ destination-comparison-operators ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define an ICMP rule:
[ sequence seq-num ] { deny | permit } icmp { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ icmp-num | icmp-type ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define an IPv6 rule:
[ sequence seq-num ] { deny | permit } IPv6 { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ fragments | routing ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]Use the following syntax to define an AHP, ESP, SCTP, protocol-name- or protocol-number rule:
[ sequence seq-num ] { deny | permit } { AHP | ESP | SCTP | protocol-name | protocol-number } { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]no sequenceseq-num- protocol-name | protocol-number
- Specifies the type of IPv6 packet you are filtering. You can specify one of the following protocol names or a valid protocol number (from 0 through 255).
- ipv6-source-prefix / prefix-length
- Specifies a source prefix and prefix length that a packet must match for the specified action (deny or permit) to occur. You must specify the ipv6-source-prefix parameter in hexadecimal using 16-bit values between colons as documented in RFC 2373. Specify the prefix-length parameter as a decimal value, preceded by a slash mark (/).
- host source-ipv6_address
- Specifies a host source IPv6 address. When you use this parameter, you do not need to specify the prefix length. A prefix length of 128 is implied.
- source-comparison-operators and destination-comparison-operators
- If you specified
tcporudp, the following optional operators are available:- gt
- Specifies port numbers equal to or greater than the port number or equal to or greater than the numeric equivalent of the port name you enter after gt.
- lt
- Specifies port numbers that are less than or equal to the port number or less than or equal to the numeric equivalent of the port name you enter after lt.
- range
- Specifies all port numbers that are between the first port name or number and the
second one you enter following the
rangekeyword. The range includes the port names or numbers you enter. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: range 23 53 (two values separated by a space). The first port number in the range must be lower than the last number in the range.
- ipv6-destination-prefix / prefix-length
- Specifies a destination prefix and prefix length that a packet must match for the specified action (deny or permit) to occur. You must specify the ipv6-destination-prefix parameter in hexadecimal using 16-bit values between colons as documented in RFC 2373. Specify the prefix-length parameter as a decimal value, preceded by a slash mark (/).
- host destination-ipv6_address
- Specifies a destination host IPv6 address. When you use this parameter, you do not need to specify the prefix length. A prefix length of 128 is implied.
- established
- (For TCP only) Filter packets that have the Acknowledgment (ACK) or Reset (RST) flag set. This policy applies only to established TCP sessions, not to new sessions.
- dscp-marking dscp-value
- Assigns the DSCP value that you specify to the packet. Values range from 0 through 63.
- 802.1p-priority-matching 802.1p-value
- Filters by 802.1p priority, for rate limiting. Values range from 0 through 7.
- 802.1p-priority-marking 802.1p-value
- Assigns the 802.1p value that you specify to the packet. Values range from 0 through 7.
- internal-priority-marking queuing-priority
- Assigns the internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
- traffic-policyname
- Enables the device to limit the rate of inbound traffic and to count the packets and bytes per packet to which ACL permit or deny clauses are applied.
ACL configuration mode
The order of the rules in an ACL is critical, as the first matching rule stops further processing. When creating rules, specifying sequence values determines the order of rule processing. If you do not specify a sequence value, the rule is added to the end of the list. Such a rule is automatically assigned the next multiple of 10 as a sequence number.
On RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.
In a rule that includes one or more of the following parameters, the
log keyword is ignored:
To enable hop-limit check for the ACL, enter the
enable nd
hop-limit command from IPv6 ACL configuration mode.
For traffic policy configuration procedures and examples, refer to "Traffic Policies" in the RUCKUS FastIron Traffic Management Configuration Guide.
To delete a rule from an ACL, do either of the following:
- Enter
no sequenceseq-value. - Type
nofollowed by the full command syntax without sequence seq-value.
For details on 802.1p rate limiting, refer to "Inspecting the 802.1p bit in the ACL for adaptive rate limiting" in the RUCKUS FastIron Traffic Management Configuration Guide.
For the
log keyword to trigger a log entry, logging must be enabled with the
logging enable command.
The following example creates an IPv6 ACL named "netw", with remarks preceding each rule.
device# configure terminal device(config)# ipv6 access-list netw device(config-ipv6-access-list netw)# remark Permits ICMP traffic from 2001:DB8:e0bb::x to 2001:DB8::x. device(config-ipv6-access-list netw)# sequence 10 permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64 device(config-ipv6-access-list netw)# remark Denies traffic from 2001:DB8:e0ac::2 to 2001:DB8:e0aa:0::24. device(config-ipv6-access-list netw)# sequence 20 deny ipv6 host 2001:DB8:e0ac::2 host 2001:DB8:e0aa:0::24 device(config-ipv6-access-list netw)# remark Denies all UDP traffic. device(config-ipv6-access-list netw)# sequence 30 deny udp any any device(config-ipv6-access-list netw)# remark Permits traffic not explicitly denied by the previous rules. device(config-ipv6-access-list netw)# sequence 40 permit ipv6 any any
The following example applies "netw" to incoming traffic on ports 1/1/2 and 1/4/3.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000-1/1/2)# ipv6 enable device(config-if-e1000-1/1/2)# ipv6 access-group netw in device(config-if-e1000-1/1/2)# exit device(config)# interface ethernet 1/4/3 device(config-if-e1000-1/4/3)# ipv6 enable device(config-if-e1000-1/4/3)# ipv6 access-group netw in
The following example creates an IPv6 ACL named "rtr", with remarks preceding each rule.
device# configure terminal device(config)# ipv6 access-list rtr device(config-ipv6-access-list rtr)# remark Denies TCP traffic from 2001:DB8:21::x to 2001:DB8:22::x. device(config-ipv6-access-list rtr)# deny tcp 2001:DB8:21::/24 2001:DB8:22::/24 device(config-ipv6-access-list rtr)# remark Denies UDP traffic from UDP ports 5 through 6 to 2001:DB8:22::/24. device(config-ipv6-access-list rtr)# deny udp any range 5 6 2001:DB8:22::/24 device(config-ipv6-access-list rtr)# remark Permits traffic not explicitly denied by the previous rules. device(config-ipv6-access-list rtr)# permit ipv6 any any
The following example applies "rtr" to incoming traffic on ports 1/2/1 and 1/2/2.
device# configure terminal device(config)# interface ethernet 1/2/1 device(config-if-e1000-1/2/1)# ipv6 enable device(config-if-e1000-1/2/1)# ipv6 access-group rtr in device(config-if-e1000-1/2/1)# exit device(config)# int eth 1/2/2 device(config-if-e1000-1/2/2)# ipv6 enable device(config-if-e1000-1/2/2)# ipv6 access-group rtr in
The following are examples of show command output for the ACL "rtr". Note that sequence numbers were automatically assigned.
device# show running-config ipv6 access-list rtr 10: deny tcp 2001:DB8:21::/24 2001:DB8:22::/24 20: deny udp any range rje 6 2001:DB8:22::/24 30:permit ipv6 any any device# show ipv6 access-list rtr ipv6 access-list rtr: 3 entries 10: deny tcp 2001:DB8:21::/24 2001:DB8:22::/24 20: deny udp any range rje 6 2001:DB8:22::/24 30: permit ipv6 any any