38-3
Catalyst 3750 Switch Software Configuration Guide
OL-8550-02
Chapter 38 Configuring IPv6 ACLs
Understanding IPv6 ACLs
IPv6 ACL Limitations
With IPv4, you can configure standard and extended numbered IP ACLs, named IP ACLs, and MAC
ACLs. IPv6 supports only named ACLs.
The switch supports most Cisco IOS-supported IPv6 ACLs with some exceptions:
•
IPv6 source and destination addresses—ACL matching is supported only on prefixes from /0 to /64
and host addresses (/128) that are in the extended universal identifier (EUI)-64 format. The switch
supports only these host addresses with no loss of information:
–
aggregatable global unicast addresses
–
link local addresses
•
The switch does not support matching on these keywords:
flowlabel
,
routing header
, and
undetermined-transport
.
•
The switch does not support reflexive ACLs (the
reflect
keyword).
•
This release supports only port ACLs and router ACLs for IPv6; it does not support VLAN ACLs
(VLAN maps).
•
The switch does not apply MAC-based ACLs on IPv6 frames.
•
You cannot apply IPv6 port ACLs to Layer 2 EtherChannels.
•
The switch does not support output port ACLs.
•
Output router ACLs and input port ACLs for IPv6 are supported only on switch stacks that are
running the advanced IP services image. Beginning with Cisco IOS Release 12.2(35)SE, switches
running the IP services or IP base image support input router ACLs for IPv6 management traffic.
•
When configuring an ACL, there is no restriction on keywords entered in the ACL, regardless of
whether or not they are supported on the platform. When you apply the ACL to an interface that
requires hardware forwarding (physical ports or SVIs), the switch checks to determine whether or
not the ACL can be supported on the interface. If not, attaching the ACL is rejected.
•
If an ACL is applied to an interface and you attempt to add an ACE with an unsupported keyword,
the switch does not allow the ACE to be added to the ACL that is currently attached to the interface.
IPv6 ACLs and Switch Stacks
The stack master supports IPv6 ACLs in hardware and distributes the IPv6 ACLs to the stack members.
Note
For full IPv6 functionality in a switch stack, all stack members must be running the advanced IP services
image. Switches running the IP services or IP base image support only input router IPv6 ACLs for IPv6
management traffic.
If a new switch takes over as stack master, it distributes the ACL configuration to all stack members. The
member switches sync up the configuration distributed by the new stack master and flush out entries that
are not required.
When an ACL is modified, attached to, or detached from an interface, the stack master distributes the
change to all stack members.
Содержание 3750G - Catalyst Integrated Wireless LAN Controller
Страница 80: ...1 28 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 1 Overview Where to Go Next ...
Страница 606: ...27 8 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 27 Configuring UDLD Displaying UDLD Status ...
Страница 670: ...31 18 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 31 Configuring SNMP Displaying SNMP Status ...
Страница 1048: ...41 20 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 41 Configuring MSDP Monitoring and Maintaining MSDP ...
Страница 1086: ...43 26 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 43 Troubleshooting Using the crashinfo Files ...
Страница 1104: ...B 4 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Appendix B Supported MIBs Using FTP to Access the MIB Files ...