Step 8
Click
Save
.
Configure IPv6 ACLs
To configure an IPv6 ACL:
Step 1
Select
Access Control > ACL
.
Step 2
Click
✚
to add an ACL.
Step 3
In the ACL name field, enter the name of the ACL.
Step 4
Choose
IPv6
as the ACL type from the ACL Type list. The IPv4 ACL's control access to the network resources are based
on the Layer 3 and Layer 4 criteria.
Step 5
Click
✚
and select the associated interfaces to apply the ACL. Next, click
OK
. If you want to change the associated
interfaces, you can click
━
to delete the selected interface then click
✚
to choose new associated interfaces.
Step 6
Click
More
to view the configuration parameters. Click
✚
to add a rule and configure the following:
If no rules are added, the DUT denies all traffic by
default.
Note
•
Rule Priority
—
When an ACL has multiple rules, the rules are applied to the packet or frame in order of priority.
A smaller number means a higher priority. The priority of the new rule will be the lowest of all explicit rules. You
can click the up or down button to change its priority. Note that there is always an implicit rule denying all traffic
with lowest priority.
•
Action
—
Choose whether to
Deny
or
Permit
the action. The default action is
Deny
.
When you choose
Permit
, the rule allows all traffic that meets the rule criteria to enter the WAP device. Traffic
that does not meet the criteria is dropped.
When you choose
Deny
, the rule blocks all traffic that meets the rule criteria from entering the WAP device. Traffic
that does not meet the criteria is forwarded unless this rule is the final rule. Because there is an implicit deny all
rule at the end of every ACL, traffic that is not explicitly permitted is dropped.
•
Service (Protocol)
—
Uses a Layer 3 or Layer 4 protocol match condition based on the value of the IP Protocol
field. You can choose one of these options:
◦
All Traffic
—
Allows all traffic that meets the rule criteria.
◦
Select From List
—
Choose one of these protocols:
IPv6, ICMPv6, TCP
, or
UDP
.
◦
Custom
—
Enter a standard IANA-assigned protocol ID from 0 to 255. Choose this method to identify a
protocol not listed in the Select From List.
•
Source IPv6 Address
—
Requires the packet's source IP address to match the address defined in the appropriate
fields.
◦
Any
—
Allows for any IP address.
◦
Single Address
—
Enter the IP address to apply this criteria.
Cisco WAP125 Wireless-AC/N Dual Band Desktop Access Point with PoE
69
Access Control
Configure IPv6 ACLs