Cisco Cisco Packet Data Gateway (PDG) 产品宣传页
IPv6 ACL Configuration Mode Commands
redirect css service (by IP packets) ▀
Cisco ASR 5x00 Command Line Interface Reference ▄
6381
dest_host_address
The IP address of the destination host to filter against expressed in IPv6 colon-separated-hexadecimal
notation.
notation.
dest_address
The IP address(es) to which the packet is to be sent.
This option is used to filter all packets to a specific IP address or a group of IP addresses.
When specifying a group of addresses, the initial address is configured using this parameter. The range can
then be configured using the
This option is used to filter all packets to a specific IP address or a group of IP addresses.
When specifying a group of addresses, the initial address is configured using this parameter. The range can
then be configured using the
dest_wildcard
parameter.
dest_wildcard
This option is used in conjunction with the
dest_address
option to specify a group of addresses for which
packets are to be filtered.
The mask must be entered as a complement:
The mask must be entered as a complement:
Zero-bits in this parameter mean that the corresponding bits configured for the
dest_address
parameter must be identical.
One-bits in this parameter mean that the corresponding bits configured for the
dest_address
parameter must be ignored.
Important:
The mask must contain a contiguous set of one-bits from the least significant bit (LSB). Therefore,
allowed masks are 0, 1, 3, 7, 15, 31, 63, 127, and 255. For example, acceptable wildcards are 0.0.0.3, 0.0.0.255, and
0.0.15.255. A wildcard of 0.0.7.15 is not acceptable since the one-bits are not contiguous.
0.0.15.255. A wildcard of 0.0.7.15 is not acceptable since the one-bits are not contiguous.
fragment
Indicates packet redirection is to be applied to IP packet fragments only.
Usage
Block IP packets when the source and destination are of interest.
Important:
A maximum of 16 rule definitions can be configured per ACL. Also note that “redirect” rule
definitions are ignored for ACLs applied to specific subscribers or all subscribers facilitated by a specific context.
Example
The following command defines a rule definition that redirects packets to the CSS service named
css-svc1
,
and IP packets coming from the host with the IP address
2002::c6a2:6419
, and fragmented packets for any
destination are matched:
redirect css service css-svc1 ip host 2002::c6a2:6419 any fragment
The following sets the insertion point to before the first rule definition above:
before redirect css service css-svc1 ip host 2002::c6a2:6419 any fragment
The following command sets the insertion point after the second rule definition above:
after redirect css service css-svc1 ip host 2002::c6a2:6419 any fragment