101 是扩展的ACL,permit ip <source ip -- wildcast> < destination ip --- wildcast>
期待高手!!
ipv6-gw-secure-srst(config)#access-list 101 permit ip ?
A.B.C.D Source address
any Any source host
host A single source host
object-group Source network object group
ipv6-gw-secure-srst(config)#access-list 101 permit ip 10.0.0.0 ?
A.B.C.D Source wildcard bits
ipv6-gw-secure-srst(config)#access-list 101 permit ip 10.0.0.0 0.0.0.0 ?
A.B.C.D Destination address
any Any destination host
host A single destination host
object-group Destination network object group
ipv6-gw-secure-srst(config)#access-list 101 permit ip 10.0.0.0 0.0.0.0 255.255.255.224 0.0.0.0 ?
dscp Match packets with given dscp value
fragments Check non-initial fragments
log Log matches against this entry
log-input Log matches against this entry, including input interface
option Match packets with given IP Options value
precedence Match packets with given precedence value
time-range Specify a time-range
tos Match packets with given TOS value
<cr>
ipv6-gw-secure-srst(config)#access-list 101 permit ip 10.0.0.0 0.0.0.0 255.255.255.224 0.0.0.0