782
Configuring IPv6 ACLs
Prerequisites
Supported ACL Features
IPv6 ACLs on the switch have these characteristics:
Fragmented frames (the
fragments
keyword as in IPv4) are supported.
The same statistics supported in IPv4 are supported for IPv6 ACLs.
If the switch runs out of hardware space, packets associated with the ACL are forwarded to the CPU, and the
software applies the ACLs.
Routed or bridged packets with hop-by-hop options have IPv6 ACLs applied in software.
Logging is supported for router ACLs, but not for port ACLs.
The switch supports IPv6 address-matching for a full range of prefix-lengths.
Note:
For items not supported for IPv6 ACLS, see
Guidelines and Limitations, page 782
Prerequisites
Guidelines and Limitations, page 782
and the Before You Begin section within each configuration
section before configuring a feature.
Guidelines and Limitations
ACLs for IPv6 Traffic Not Supported
The switch does not support VLAN ACLs (VLAN maps) for IPv6 traffic.
The switch does not apply MAC-based ACLs on IPv6 frames.
You cannot apply IPv6 port ACLs to Layer 2 EtherChannels.
The switch does not support output port ACLs.
Cisco IOS IPv6 ACLs Functions Not Supported
The switch does not support matching on these keywords:
flowlabel
,
routing header
, and
undetermined-transport
.
The switch does not support reflexive ACLs (the
reflect
keyword).
Access Control Entry (ACE) and ACLs
When you apply an ACL to an interface and you attempt to add an access control entry (ACE) with an unsupported
keyword, the switch does not allow the ACE to be added to the attached ACL.
Named ACLs
IPv6 supports only named ACLs.
IPv6 ACLs Interactions With Other Switches or Features
When you configure an IPv6 router ACL to deny a packet, the software does not route the packet. Instead, the
software forwards a copy of the packet to the Internet Control Message Protocol (ICMP) queue to generate an ICMP
unreachable message for the frame.
If a bridged frame is to be dropped due to a port ACL, the frame is not bridged.
Содержание IE 4000
Страница 12: ...8 Configuration Overview Default Settings After Initial Switch Configuration ...
Страница 52: ...48 Configuring Interfaces Monitoring and Maintaining the Interfaces ...
Страница 108: ...104 Configuring Switch Clusters Additional References ...
Страница 128: ...124 Performing Switch Administration Additional References ...
Страница 130: ...126 Configuring PTP ...
Страница 140: ...136 Configuring CIP Additional References ...
Страница 146: ...142 Configuring SDM Templates Configuration Examples for Configuring SDM Templates ...
Страница 192: ...188 Configuring Switch Based Authentication Additional References ...
Страница 244: ...240 Configuring IEEE 802 1x Port Based Authentication Additional References ...
Страница 274: ...270 Configuring SGT Exchange Protocol over TCP SXP and Layer 3 Transport Configuring Cisco TrustSec Caching ...
Страница 298: ...294 Configuring VLANs Additional References ...
Страница 336: ...332 Configuring STP Additional References ...
Страница 408: ...404 Configuring DHCP Additional References ...
Страница 450: ...446 Configuring IGMP Snooping and MVR Additional References ...
Страница 490: ...486 Configuring SPAN and RSPAN Additional References ...
Страница 502: ...498 Configuring Layer 2 NAT ...
Страница 559: ...555 Configuring Network Security with ACLs How to Configure Network Security with ACLs Creating a Numbered Extended ACL ...
Страница 770: ...766 Configuring IPv6 MLD Snooping Related Documents ...
Страница 930: ...926 Configuring IP Unicast Routing Related Documents ...
Страница 956: ...952 Configuring IPv6 Unicast Routing Configuring IPv6 network 2010 AB8 2 48 network 2010 AB8 3 48 exit address family ...
Страница 976: ...972 Configuring Cisco IOS IP SLAs Operations Additional References ...
Страница 978: ...974 Dying Gasp ...
Страница 990: ...986 Configuring Enhanced Object Tracking Monitoring Enhanced Object Tracking ...
Страница 994: ...990 Configuring MODBUS TCP Displaying MODBUS TCP Information ...
Страница 996: ...992 Ethernet CFM ...
Страница 1030: ...1026 Working with the Cisco IOS File System Configuration Files and Software Images Working with Software Images ...
Страница 1066: ...1062 Using an SD Card SD Card Alarms ...