F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices Access Control Configuration Guide-6PW100

28
Destination net unreachable.
Ping statistics for 1000::100:
Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
The output shows the database server cannot be pinged.
# Display configuration and match statistics for IPv6 advanced ACL 3000 on Device A during working
hours.
[Firewall] display acl ipv6 3000
Advanced IPv6 ACL 3000, named -none-, 3 rules,
ACL's step is 5
rule 0 permit ipv6 source 1001::/16 destination 1000::100/128
rule 5 permit ipv6 source 1002::/16 destination 1000::100/128 time-range work (4 times
matched) (Active)
rule 10 deny ipv6 destination 1000::100/128 (4 times matched)
The output shows rule 5 is active. Rule 5 and rule 10 have been matched four times as the result of the
ping operations.
22B
Configuration guidelines
When you configure an ACL, follow these guidelines:
You cannot create a rule with, or modify a rule to have, the same permit/deny statement as an
existing rule in the ACL.
You can only modify the existing rules of an ACL that uses the rule order of config. When you
modify a rule of such an ACL, you may choose to change just some of the settings, in which case
the other settings remain the same.