data:image/s3,"s3://crabby-images/e5e99/e5e997fccff7dc313d6f8b874c29138db11be25d" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 197"
10-5
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 10 Configuring IPv6
Configuring IPv6 Default and Static Routes
Configuring IPv6 Default and Static Routes
IPv6 unicast routing is always enabled. FWSM routes IPv6 traffic between interfaces as long as the
interfaces are enabled for IPv6 and the IPv6 access lists allow the traffic. You can add a default route
and static routes using the
ipv6 route
command.
To configure an IPv6 default route and static routes, perform the following steps:
Step 1
To add the default route, use the following command:
hostname(config)#
ipv6 route
interface_name
::/0
next_hop_ipv6_addr
The address ::/0 is the IPv6 equivalent of “any.”
Step 2
(Optional) Define IPv6 static routes. Use the following command to add an IPv6 static route to the IPv6
routing table:
hostname(config)#
ipv6 route
if_name
destination next_hop_ipv6_addr
[
admin_distance
]
Note
The
ipv6 route
command works like the
route
command used to define IPv4 static routes.
See the
“Example 4: IPv6 Configuration Example” section on page B-13
for an example of the
ipv6
route
command used to configure the default route.
Configuring IPv6 Access Lists
Configuring an IPv6 access list is similar configuring an IPv4 access, but with IPv6 addresses.
To configure an IPv6 access list, perform the following steps:
Step 1
Create an access entry. To create an access list, use the
ipv6 access-list
command to create entries for
the access list. There are two main forms of this command to choose from, one for creating access list
entries specifically for ICMP traffic, and one to create access list entries for all other types of IP traffic.
•
To create an IPv6 access list entry specifically for ICMP traffic, enter the following command:
hostname(config)#
ipv6 access-list
id
[
line
num] {
permit
|
deny
}
icmp
source
destination
[
icmp_type
]
•
To create an IPv6 access list entry, enter the following command:
hostname(config)#
ipv6 access-list
id
[
line
num
] {
permit
|
deny
}
protocol
source
[
src_port
]
destination
[
dst_port
]
The following describes the arguments for the
ipv6 access-list
command:
•
id—The name of the access list. Use the same id in each command when you are entering multiple
entries for an access list.
•
line
num
—When adding an entry to an access list, you can specify the line number in the list where
the entry should appear.
•
permit
|
deny
—Determines whether the specified traffic is blocked or allowed to pass.
•
icmp
—Indicates that the access list entry applies to ICMP traffic.
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......