•
Layer 3 Ethernet interfaces and subinterfaces
•
Layer 3 Ethernet port-channel interfaces and subinterfaces
•
Tunnels
•
Management interfaces
However, an ACL applied to a Layer 3 interface with the
ipv6 port traffic-filter
command is inactive unless
the port mode changes to access or trunk (Layer 2) mode. To apply an IPv6 ACL as a router ACL, use the
ipv6 traffic-filter
command.
You can also apply an IPv6 ACL as a VLAN ACL. For more information, see the
match (VLAN access-map)
command.
The device applies port ACLs to inbound traffic only. The device checks inbound packets against the rules
in the ACL. If the first matching rule permits the packet, the device continues to process the packet. If the
first matching rule denies the packet, the device drops the packet and returns an ICMP host-unreachable
message.
If you delete the specified ACL from the device without removing the ACL from an interface, the deleted
ACL does not affect traffic on the interface.
If MAC packet classification is enabled on a Layer 2 interface, you cannot use the
ipv6 port traffic-filter
command on the interface.
This command does not require a license.
Examples
This example shows how to apply an IPv6 ACL named ipv6-acl-L2 to Ethernet interface 1/3:
switch#
configure terminal
switch(config)#
interface ethernet 1/3
switch(config-if)#
ipv6 port traffic-filter ipv6-acl-L2 in
This example shows how to remove an IPv6 ACL named ipv6-acl-L2 from Ethernet interface 1/3:
switch#
configure terminal
switch(config)#
interface ethernet 1/3
switch(config-if)#
no
ipv6 port traffic-filter ipv6-acl-L2 in
switch(config)#
show running-config interface ethernet 2/3
!Command: show running-config interface Ethernet2/3
!Time: Wed Jun 24 13:13:48 2009
version 4.2(1)
interface Ethernet2/3
ip access-group ipacl in
mac port access-group macacl
switchport
mac packet-classify
switch(config)#
interface ethernet 2/3
switch(config-if)#
ipv6 port traffic-filter v6acl in
ERROR: The given policy cannot be applied as mac packet classification is enable
d on this port
switch(config-if)#
Related Commands
Description
Command
Configures an IPv6 ACL.
ipv6 access-list
Cisco Nexus 7000 Series Security Command Reference
460
I Commands
ipv6 port traffic-filter
Содержание Nexus 7000 Series
Страница 2: ... Cisco Systems Inc All rights reserved ...
Страница 20: ...Cisco Nexus 7000 Series Security Command Reference xx Contents ...
Страница 62: ...Cisco Nexus 7000 Series Security Command Reference 36 A Commands aaa authentication rejected ...
Страница 78: ...Cisco Nexus 7000 Series Security Command Reference 52 A Commands aaa user default role ...
Страница 157: ...Cisco Nexus 7000 Series Security Command Reference 131 C Commands crypto ca import ...
Страница 172: ...Cisco Nexus 7000 Series Security Command Reference 146 C Commands cts role based sgt map ...
Страница 186: ...Cisco Nexus 7000 Series Security Command Reference 160 C Commands cts role based access list ...
Страница 190: ...Cisco Nexus 7000 Series Security Command Reference 164 C Commands cts role based detailed logging ...
Страница 256: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 230 D Commands deny IPv4 ...
Страница 271: ...protocol Cisco Nexus 7000 Series Security Command Reference 245 D Commands deny IPv6 ...
Страница 274: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 248 D Commands deny IPv6 ...
Страница 291: ...Cisco Nexus 7000 Series Security Command Reference 265 D Commands description identity policy ...
Страница 293: ...Cisco Nexus 7000 Series Security Command Reference 267 D Commands description user role ...
Страница 299: ...Cisco Nexus 7000 Series Security Command Reference 273 D Commands device role ...
Страница 313: ...Cisco Nexus 7000 Series Security Command Reference 287 E Commands enable Cert DN match ...
Страница 340: ...Cisco Nexus 7000 Series Security Command Reference 314 E Commands eq ...
Страница 344: ...Cisco Nexus 7000 Series Security Command Reference 318 F Commands feature cts ...
Страница 350: ...Cisco Nexus 7000 Series Security Command Reference 324 F Commands feature ldap ...
Страница 369: ...G Commands gt page 344 Cisco Nexus 7000 Series Security Command Reference 343 ...
Страница 372: ...Cisco Nexus 7000 Series Security Command Reference 346 G Commands gt ...
Страница 398: ...Cisco Nexus 7000 Series Security Command Reference 372 I Commands interface policy deny ...
Страница 454: ...Cisco Nexus 7000 Series Security Command Reference 428 I Commands ip udp relay subnet broadcast ...
Страница 470: ...Cisco Nexus 7000 Series Security Command Reference 444 I Commands ipv6 dhcp ldra attach policy interface ...
Страница 497: ...Cisco Nexus 7000 Series Security Command Reference 471 K Commands key config key ...
Страница 504: ...Cisco Nexus 7000 Series Security Command Reference 478 K Commands key string ...
Страница 518: ...Cisco Nexus 7000 Series Security Command Reference 492 L Commands It ...
Страница 536: ...Cisco Nexus 7000 Series Security Command Reference 510 M Commands monitor session ...
Страница 537: ...N Commands nac enable page 512 neq page 513 Cisco Nexus 7000 Series Security Command Reference 511 ...
Страница 543: ...Cisco Nexus 7000 Series Security Command Reference 517 O Commands object group identity policy ...
Страница 552: ...Cisco Nexus 7000 Series Security Command Reference 526 O Commands other config flag ...
Страница 569: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 543 P Commands permit IPv4 ...
Страница 584: ...protocol Cisco Nexus 7000 Series Security Command Reference 558 P Commands permit IPv6 ...
Страница 587: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 561 P Commands permit IPv6 ...
Страница 622: ...Cisco Nexus 7000 Series Security Command Reference 596 P Commands propagate sgt ...
Страница 664: ...Cisco Nexus 7000 Series Security Command Reference 638 R Commands rule ...
Страница 714: ...Cisco Nexus 7000 Series Security Command Reference 688 S Commands switchport port security violation ...
Страница 737: ...Cisco Nexus 7000 Series Security Command Reference 711 Show Commands show arp access lists ...
Страница 841: ...Cisco Nexus 7000 Series Security Command Reference 815 Show Commands show ipv6 dhcp ldra ...
Страница 992: ...Cisco Nexus 7000 Series Security Command Reference 966 T Commands trustedCert ...
Страница 1015: ...Cisco Nexus 7000 Series Security Command Reference 989 V Commands vlan policy deny ...
Страница 1017: ...Cisco Nexus 7000 Series Security Command Reference 991 V Commands vrf policy deny ...
Страница 1018: ...Cisco Nexus 7000 Series Security Command Reference 992 V Commands vrf policy deny ...