Reference Guide
format. The range is /0 to /128. The :: notation specifies successive
hexadecimal fields of zero.
mask
Enter a network mask in /prefix format (/x).
host
ipv6-address
Enter the keyword host followed by the IPv6 address of the host in
the x:x:x:x::x format. The :: notation specifies successive hexadecimal
fields of zero.
destination
address
Enter the IPv6 address of the network or host to which the packets
are sent in the x:x:x:x::x format followed by the prefix length in the /x
format. The range is /0 to /128. The :: notation specifies successive
hexadecimal fields of zero.
message-type
(OPTIONAL) Enter an ICMP message type, either with the type (and
code, if necessary) numbers or with the name of the message type.
The range is 0 to 255 for ICMP type and 0 to 255 for ICMP code.
count (OPTIONAL) Enter the keyword count to count packets processed
by the filter.
byte (OPTIONAL) Enter the keyword byte to count bytes processed by
the filter.
log (OPTIONAL) Enter the keyword log to have the information kept in an
ACL log file.
monitor (OPTIONAL) Enter the keyword monitor to monitor traffic on the
monitoring interface specified in the flow-based monitoring session
along with the filter operation.
Defaults Not configured.
Command Modes ACCESS-LIST
Command History
Version 8.3.7.0 Introduced on the S4810.
Version 8.4.2.1 Introduced on the S-Series.
Version 8.2.1.0 Introduced on the E-Series ExaScale.
Version 7.8.1.0 Introduced on the C-Series.
Version 7.4.1.0 Introduced on the E-Series TeraScale. Added the monitor option.
Usage
Information
The C-Series cannot count both packets and bytes, so when you enter the count byte
options, only bytes are incremented.
permit tcp
Configure a filter to pass TCP packets that match the filter criteria.
C-Series, E-Series, S-Series
Syntax
permit tcp {source address mask | any | host ipv6-address}
[operator port [port]] {destination address | any | host ipv6-
926










