ipv6 access-group

Applies an IPv6 ACL to an interface.
Syntax
ipv6 access-group { name } { in | out } [ logging enable ]
no ipv6 access-group { name } { in | out } [ logging enable ]
Parameters
name
Specifies the name of the IPv6 ACL being defined.
in
Applies the IPv6 ACL to incoming traffic.
out
Applies the IPv6 ACL to outbound traffic.
[logging enable]
Turns logging on for matched statements in the ACL that also include a log action.
Modes

Global configuration mode

Interface configuration sub-modes

Multiple interface configuration mode

Usage Guidelines

The no form of the command removes the IPv6 ACL.

From FastIron release 08.0.95, the ipv6 access-group command replaces the ipv6 traffic-filter command.

In multiple interface configuration (MIF) mode, ACLs can be bound only to inbound traffic.

If you attempt to apply an egress ACL in multiple interface configuration mode, an error message is displayed.

In multiple interface configuration mode, you can configure a maximum range of eight interfaces with the same ACL simultaneously.

In multiple interface configuration mode, all interfaces are checked before the ACL is applied, and if an interface is not eligible for the ACL to be applied, binding fails on all designated intefaces, and an error message is displayed.

If an ACL is removed from multiple interfaces simultaneously but cannot be removed from one or more of the interfaces, the unbind operation nevertheless succeeds on the other designated interfaces.

Examples

The following example creates an IPv6 access-list and enables accounting.

device# configure terminal
device(config)# ipv6 access-list aclv6log
device(config-ipv6-access-list aclv6log)# enable accounting
device(config-ipv6-access-list aclv6log)# exit
device(config)#

The following example applies the IPv6 ACL netw to inbound traffic on ports 1/1/2 and 1/43.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000-1/1/2)# ipv6 enable
device(config-if-e1000-1/1/2)# ipv6 access-group netw in
device(config-if-e1000-1/1/2)# exit
device(config)# interface ethernet 1/4/3
device(config-if-e1000-1/4/3)# ipv6 enable
device(config-if-e1000-1/4/3)# ipv6 access-group netw in

The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.

device# configure terminal
device(config)# vlan 555 by port
device(config-vlan-555)# tagged ethe 1/2/2 lag 10
device(config-vlan-555)# interface ve 555
device(config-vlan-555)# ipv6 access-group scale25 in
device(config-vlan-555)# ipv6 access-group scale15 out
device(config-vlan-555)# mac access-group mac_acl1 in
device(config-vlan-555)# ip access-group 123 in
device(config-vlan-555)# ip access-group 134 out
device(config-vlan-555)# exit
device(config)# 

The following example applies IPv6, IPv4, and MAC ACLs to tagged Ethernet port 1/2/2 specifically within LAG 10 and enables logging of traffic that matches statements that contain the log keyword within the applied ACLs.

device# configure terminal
device(config)# vlan 558 by port
device(config-vlan-558)# tagged ethe 1/2/2 lag 10
device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable
device(config-vlan-558)# mac access-group mac_acl in lag 10
device(config-vlan-558)# ip access-group 134 in lag 10 logging enable

The following example binds an IPv6 ACL to multiple interfaces.

Need a viable example and description from SMEs. Also need list of limitations and guidelines.

device# configure terminal
device(config)# interface ethernet 1/1/15 to 1/1/20 
device(config-mif-1/1/15-1/1/20)# ipv6 access-group V6-ACL in
Warning: Binding of large ACL Operation may take few minutes 

SYSLOG: <14> Sep 25 01:33:32 device ACL: V6-ACL applied to eth 1/1/15.  

SYSLOG: <14> Sep 25 01:33:32 device ACL: V6-ACL applied to eth 1/1/16.  

SYSLOG: <14> Sep 25 01:33:32 device ACL: V6-ACL applied to eth 1/1/17.  

SYSLOG: <14> Sep 25 01:33:32 device ACL: V6-ACL applied to eth 1/1/18.  

SYSLOG: <14> Sep 25 01:33:32 device ACL: V6-ACL applied to eth 1/1/19.  

SYSLOG: <14> Sep 25 01:33:32 device ACL: V6-ACL applied to eth 1/1/20.
device(config-mif-1/1/15-1/1/20)# end 
History
Release version Command history
08.0.95 This command was introduced to replace the ipv6 traffic-filter command.
10.0.20 The command was modified to add the multiple inteface configuration option.