F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices Access Control Command Reference-6PW100
22
Parameters Function Descri
p
tion
counting
Counts the number of times
the ACL rule has been
matched. This option is
disabled by default.
N/A
dscp dscp
Specifies a DSCP
preference.
The dscp argument can be a number in the range of 0 to
63, or in words, af11 (10), af12 (12), af13 (14), af21
(18), af22 (20), af23 (22), af31 (26), af32 (28), af33
(30), af41 (34), af42 (36), af43 (38), cs1 (8), cs2 (16), cs3
(24), cs4 (32), cs5 (40), cs6 (48), cs7 (56), default (0), or
ef (46).
flow-label
flow-label-value
Specifies a flow label value
in an IPv6 packet header.
The flow-label-value argument is in the range of 0 to
1048575.
logging Logs matching packets.
This function requires that the module that uses the ACL
supports logging.
routing [ type
routing-type ]
Specifies the type of routing
header.
The routing-type argument takes a value in the range of 0
to 255.
If no routing type header is specified, the rule applies to the
IPv6 packets with any type of routing header.
fragment
Applies the rule to only
non-first fragments.
Without this keyword, the rule applies to all fragments and
non-fragments.
time-range
time-range-name
Specifies a time range for
the rule.
The time-range-name argument takes a case-insensitive
string of 1 to 32 characters. It must start with an English
letter. If the time range is not configured, the system creates
the rule. However, the rule using the time range can take
effect only after you configure the timer range.
vpn-instance
vpn-instance-name
Applies the rule to packets
in a VPN instance.
The vpn-instance-name argument takes a case-sensitive
string of 1 to 31 characters.
If no VPN instance is specified, the rule applies to non-VPN
packets.
If the protocol argument takes tcp (6) or udp (17), set the parameters shown in Table 9.