The IPv6 ACL Extensions for Hop by Hop Filtering feature implements RFC 2460 to support traffic filtering
in any upper-layer protocol type.
How to Configure IPv6 ACLs
Configuring IPv6 ACLs
To filter IPv6 traffic, you perform these steps:
SUMMARY STEPS
1.
enable
2.
configure terminal
3.
{
ipv6 access-list list-name
4.
{
deny
|
permit
} protocol {
source-ipv6-prefix/
|
prefix-length
|
any
|
host source-ipv6-address
} [ operator [
port-number
]] {
destination-ipv6-prefix/ prefix-length
|
any
|
host destination-ipv6-address
} [operator
[
port-number
]][
dscp value
] [
fragments
] [
log
] [
log-input
] [
routing
] [
sequence value
] [
time-range name
]
5.
{
deny
|
permit
}
tcp
{
source-ipv6-prefix/prefix-length
|
any
|
host source-ipv6-address
} [
operator
[
port-number
]] {
destination-ipv6- prefix/prefix-length
|
any
|
host destination-ipv6-address
} [operator
[
port-number
]] [
ack
] [
dscp value
] [
established
] [
fin
] [
log
] [
log-input
] [
neq
{
port
| protocol}] [
psh
]
[
range
{
port
| protocol}] [
rst
] [
routing
] [
sequence value
] [
syn
] [
time-range name
] [
urg
]
6.
{
deny
|
permit
}
udp
{
source-ipv6-prefix/prefix-length
|
any
|
host source-ipv6-address
} [operator
[
port-number
]] {
destination-ipv6-prefix/prefix-length
|
any
|
host destination-ipv6-address
} [operator
[
port-number
]] [
dscp value
] [
log
] [
log-input
] [
neq
{
port
|
protocol
}] [
range
{
port
|
protocol
}] [
routing
]
[
sequence value
] [
time-range name
]]
7.
{
deny
|
permit
}
icmp
{
source-ipv6-prefix/prefix-length
|
any
|
host source-ipv6-address
} [operator
[
port-number
]] {
destination-ipv6-prefix/prefix-length
|
any
|
host destination-ipv6-address
} [operator
[
port-number
]] [
icmp-type
[
icmp-code
] | icmp-message] [
dscp value
] [
log
] [
log-input
] [
routing
] [
sequence
value
] [
time-range name
]
8.
end
9.
show ipv6 access-list
10.
show running-config
11.
copy running-config startup-config
DETAILED STEPS
Purpose
Command or Action
Enables privileged EXEC mode. Enter your password if prompted.
enable
Step 1
Example:
Switch>
enable
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1222
How to Configure IPv6 ACLs
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......