3-4z You can only modify the existing rules of an ACL that uses the match order of config. Whenmodifying a rule of such an ACL, you may choose to change just some of the settings, in whichcase the other settings remain the same.z You cannot create a rule with, or modify a rule to have, the same permit/deny statement as anexisting rule in the ACL.z When the ACL match order is auto, a newly created rule will be inserted among the existing rules inthe depth-first match order. Note that the IDs of the rules still remain the same.z You can modify the match order of an IPv6 ACL with the acl ipv6 number acl6-number [ nameacl6-name ] match-order { auto | config } command, but only when the ACL does not contain anyrules.z The rule specified in the rule comment command must already exist.Configuration Example# Configure IPv6 ACL 3000 to permit TCP packets with the source address of 2030:5060::9050/64. system-view[Sysname] acl ipv6 number 3000[Sysname-acl6-adv-3000] rule permit tcp source 2030:5060::9050/64# Verify the configuration.[Sysname-acl6-adv-3000] display acl ipv6 3000Advanced IPv6 ACL 3000, named -none-, 1 rule,ACL's step is 5rule 0 permit tcp source 2030:5060::9050/64 (5 times matched)Configuring an Ethernet Frame Header ACLFor the Ethernet frame header ACL configuration, refer to Configuring an Ethernet Frame Header ACL.Copying an IPv6 ACLThis feature allows you to copy an existing IPv6 ACL to generate a new one, which is of the same typeand has the same match order, rules, rule numbering step, and descriptions as the source IPv6 ACL.Configuration PrerequisitesMake sure that the source IPv6 ACL exists while the destination IPv6 ACL does not.Configuration ProcedureFollow these steps to copy an IPv6 ACL:To do… Use the command… RemarksEnter system view system-view —