sequence (permit | deny in IPv6 ACLs)

Inserts filtering rules in IPv6 access control lists (ACLs).
Syntax

Use the following syntax to define a TCP or UDP rule:

[sequence seq-num ] { deny | permit } { tcp | udp } { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } [ source-comparison-operators ] { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ established ] [ destination-comparison-operators ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax to define an ICMP rule:

[ sequence seq-num ] { deny | permit } icmp { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ icmp-num | icmp-type ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax to define an IPv6 rule:

[ sequence seq-num ] { deny | permit } IPv6 { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ fragments | routing ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax to define an AHP, ESP, SCTP, protocol-name- or protocol-number rule:

[ sequence seq-num ] { deny | permit } { AHP | ESP | SCTP | protocol-name | protocol-number } { ipv6-source-prefix / prefix-length | host source-ipv6_address | any } { ipv6-destination-prefix / prefix-length | host ipv6-destination-address | any } [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ traffic-policy name ] [ log ] [ mirror ]
no sequenceseq-num
Parameters
sequence
(Optional) Enables you to assign a sequence number to the rule.
seq-num
Valid values range from 1 through 65000.
deny
Specifies rules to deny traffic.
permit
Specifies rules to permit traffic.
protocol-name | protocol-number
Specifies the type of IPv6 packet you are filtering. You can specify one of the following protocol names or a valid protocol number (from 0 through 255).
  • ahp: Authentication Header
  • esp: Encapsulating Security Payload
  • icmp: Internet Control Message Protocol
  • ipv6: Internet Protocol, version 6
  • sctp: Stream Control Transmission Protocol
  • tcp: Transmission Control Protocol
  • udp: User Datagram Protocol
ipv6-source-prefix / prefix-length
Specifies a source prefix and prefix length that a packet must match for the specified action (deny or permit) to occur. You must specify the ipv6-source-prefix parameter in hexadecimal using 16-bit values between colons as documented in RFC 2373. Specify the prefix-length parameter as a decimal value, preceded by a slash mark (/).
host source-ipv6_address
Specifies a host source IPv6 address. When you use this parameter, you do not need to specify the prefix length. A prefix length of 128 is implied.
any
Specifies all source addresses.
source-comparison-operators and destination-comparison-operators
If you specified tcp or udp, the following optional operators are available:
eq
Specifies the port name or number you enter after eq.
gt
Specifies port numbers equal to or greater than the port number or equal to or greater than the numeric equivalent of the port name you enter after gt.
lt
Specifies port numbers that are less than or equal to the port number or less than or equal to the numeric equivalent of the port name you enter after lt.
neq
Specifies all port numbers except the port number or port name you enter after neq.
range
Specifies all port numbers that are between the first port name or number and the second one you enter following the range keyword. The range includes the port names or numbers you enter. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: range 23 53 (two values separated by a space). The first port number in the range must be lower than the last number in the range.
ipv6-destination-prefix / prefix-length
Specifies a destination prefix and prefix length that a packet must match for the specified action (deny or permit) to occur. You must specify the ipv6-destination-prefix parameter in hexadecimal using 16-bit values between colons as documented in RFC 2373. Specify the prefix-length parameter as a decimal value, preceded by a slash mark (/).
host destination-ipv6_address
Specifies a destination host IPv6 address. When you use this parameter, you do not need to specify the prefix length. A prefix length of 128 is implied.
any
Specifies all destination addresses.
established
(For TCP only) Filter packets that have the Acknowledgment (ACK) or Reset (RST) flag set. This policy applies only to established TCP sessions, not to new sessions.
icmp-num
Specifies a numbered message type.
icmp-type
(For ICMP only) Specifies a named message type, from the following list.
beyond-scope
Specifies a beyond scope message.
destination-unreachable
Specifies a destination unreachable message.
echo-reply
Specifies an echo reply.
echo-request
Specifies an echo request (ping).
header
Specifies a parameter problem header error message.
hop-limit
Specifies an in-transit, time exceeded message.
mld-query
Specifies an MLD query message.
mld-reduction
Specifies an MLD reduction message.
mld-report
Specifies an MLD report message.
nd-na
Specifies a neighbor discovery (ND) neighbor advertisement message.
nd-ns
Specifies an ND neighbor solicitation message.
next-header
Specifies a parameter problem next-header error message.
no-admin
Specifies a destination unreachable administratively prohibited message.
no-route
Specifies a destination unreachable no route message.
packet-too-big
Specifies a packet too big message.
parameter-option
Specifies a parameter-option problem message.
parameter-problem
Specifies a parameter problem message.
port-unreachable
Specifies a destination-port unreachable message.
reassembly-timeout
Specifies a reassembly timeout message.
renum-command
Specifies a renumber command message.
renum-result
Specifies a renumber result message.
renum-seq-number
Specifies a renumber sequence number message.
router-advertisement
Specifies a router advertisment message.
router-renumbering
Specifies a router renumbering message.
router-solicitation
Specifies a router solicitation message.
time-exceeded
Specifies a time exceeded message.
unreachable
Specifies a destination-unreachable message.
fragments
(For IPv6 protocol only) Specifies fragmented packets that contain a non-zero offset.
routing
(For IPv6 protocol only) Specifies source-routed packets.
dscp-matching dscp-value
Filters by DSCP value. Values range from 0 through 63.
dscp-marking dscp-value
Assigns the DSCP value that you specify to the packet. Values range from 0 through 63.
802.1p-priority-matching 802.1p-value
Filters by 802.1p priority, for rate limiting. Values range from 0 through 7.
802.1p-priority-marking 802.1p-value
Assigns the 802.1p value that you specify to the packet. Values range from 0 through 7.
internal-priority-marking queuing-priority
Assigns the internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
traffic-policyname
Enables the device to limit the rate of inbound traffic and to count the packets and bytes per packet to which ACL permit or deny clauses are applied.
log
Enables SNMP traps and syslog messages for the rule.
mirror
Mirrors packets matching the rule.
Modes

ACL configuration mode

Usage Guidelines

The order of the rules in an ACL is critical, as the first matching rule stops further processing. When creating rules, specifying sequence values determines the order of rule processing. If you do not specify a sequence value, the rule is added to the end of the list. Such a rule is automatically assigned the next multiple of 10 as a sequence number.

On RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.

In a rule that includes one or more of the following parameters, the log keyword is ignored:

  • dscp-matching
  • dscp-marking
  • 802.1p-priority-matching
  • 802.1p-priority-marking

To enable hop-limit check for the ACL, enter the enable nd hop-limit command from IPv6 ACL configuration mode.

For traffic policy configuration procedures and examples, refer to "Traffic Policies" in the RUCKUS FastIron Traffic Management Configuration Guide.

To delete a rule from an ACL, do either of the following:

  • Enter no sequence seq-value.
  • Type no followed by the full command syntax without sequence seq-value.

For details on 802.1p rate limiting, refer to "Inspecting the 802.1p bit in the ACL for adaptive rate limiting" in the RUCKUS FastIron Traffic Management Configuration Guide.

For the log keyword to trigger a log entry, logging must be enabled with the logging enable command.

Examples

The following example creates an IPv6 ACL named "netw", with remarks preceding each rule.

device# configure terminal
device(config)# ipv6 access-list netw

device(config-ipv6-access-list netw)# remark Permits ICMP traffic from 2001:DB8:e0bb::x to 2001:DB8::x.
device(config-ipv6-access-list netw)# sequence 10 permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64

device(config-ipv6-access-list netw)# remark Denies traffic from 2001:DB8:e0ac::2 to 2001:DB8:e0aa:0::24.
device(config-ipv6-access-list netw)# sequence 20 deny ipv6 host 2001:DB8:e0ac::2 host 2001:DB8:e0aa:0::24

device(config-ipv6-access-list netw)# remark Denies all UDP traffic.
device(config-ipv6-access-list netw)# sequence 30 deny udp any any

device(config-ipv6-access-list netw)# remark Permits traffic not explicitly denied by the previous rules.
device(config-ipv6-access-list netw)# sequence 40 permit ipv6 any any

The following example applies "netw" to incoming traffic on ports 1/1/2 and 1/4/3.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000-1/1/2)# ipv6 enable
device(config-if-e1000-1/1/2)# ipv6 access-group netw in
device(config-if-e1000-1/1/2)# exit
device(config)# interface ethernet 1/4/3
device(config-if-e1000-1/4/3)# ipv6 enable
device(config-if-e1000-1/4/3)# ipv6 access-group netw in

The following example creates an IPv6 ACL named "rtr", with remarks preceding each rule.

device# configure terminal
device(config)# ipv6 access-list rtr

device(config-ipv6-access-list rtr)# remark Denies TCP traffic from 2001:DB8:21::x to 2001:DB8:22::x.
device(config-ipv6-access-list rtr)# deny tcp 2001:DB8:21::/24 2001:DB8:22::/24

device(config-ipv6-access-list rtr)# remark Denies UDP traffic from UDP ports 5 through 6 to 2001:DB8:22::/24.
device(config-ipv6-access-list rtr)# deny udp any range 5 6 2001:DB8:22::/24

device(config-ipv6-access-list rtr)# remark Permits traffic not explicitly denied by the previous rules.
device(config-ipv6-access-list rtr)# permit ipv6 any any

The following example applies "rtr" to incoming traffic on ports 1/2/1 and 1/2/2.

device# configure terminal
device(config)# interface ethernet 1/2/1
device(config-if-e1000-1/2/1)# ipv6 enable
device(config-if-e1000-1/2/1)# ipv6 access-group rtr in
device(config-if-e1000-1/2/1)# exit
device(config)# int eth 1/2/2
device(config-if-e1000-1/2/2)# ipv6 enable
device(config-if-e1000-1/2/2)# ipv6 access-group rtr in

The following are examples of show command output for the ACL "rtr". Note that sequence numbers were automatically assigned.

device# show running-config
ipv6 access-list rtr
10: deny tcp 2001:DB8:21::/24 2001:DB8:22::/24
20: deny udp any range rje 6 2001:DB8:22::/24
30:permit ipv6 any any

device# show ipv6 access-list rtr
ipv6 access-list rtr: 3 entries
10: deny tcp 2001:DB8:21::/24 2001:DB8:22::/24
20: deny udp any range rje 6 2001:DB8:22::/24
30: permit ipv6 any any
History
Release version Command history
08.0.50 This command was modified to support the sequence keyword and to support logging in permit rules.