ipv6 access-group
ipv6 access-group{name}{in|out}[logging enable]no ipv6 access-group{name}{in|out}[logging enable]Global configuration mode
Interface configuration sub-modes
The
no form of the command removes the IPv6 ACL.
From FastIron release 08.0.95, the
ipv6 access-group command replaces the
ipv6 traffic-filter command.
The following example creates an IPv6 access-list and enables accounting.
device# configure terminal device(config)# ipv6 access-list aclv6log device(config-ipv6-access-list aclv6log)# enable accounting device(config-ipv6-access-list aclv6log)# exit device(config)#
The following example applies the IPv6 ACL netw to inbound traffic on ports 1/1/2 and 1/43.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000-1/1/2)# ipv6 enable device(config-if-e1000-1/1/2)# ipv6 access-group netw in device(config-if-e1000-1/1/2)# exit device(config)# interface ethernet 1/4/3 device(config-if-e1000-1/4/3)# ipv6 enable device(config-if-e1000-1/4/3)# ipv6 access-group netw in
The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.
device# configure terminal device(config)# vlan 555 by port device(config-vlan-555)# tagged ethe 1/2/2 lag 10 device(config-vlan-555)# interface ve 555 device(config-vlan-555)# ipv6 access-group scale25 in device(config-vlan-555)# ipv6 access-group scale15 out device(config-vlan-555)# mac access-group mac_acl1 in device(config-vlan-555)# ip access-group 123 in device(config-vlan-555)# ip access-group 134 out device(config-vlan-555)# exit device(config)#
The following example applies IPv6, IPv4, and MAC ACLs to tagged Ethernet port 1/2/2 specifically within LAG 10 and enables logging of traffic that matches statements that contain the log keyword within the applied ACLs.
device# configure terminal device(config)# vlan 558 by port device(config-vlan-558)# tagged ethe 1/2/2 lag 10 device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable device(config-vlan-558)# mac access-group mac_acl in lag 10 device(config-vlan-558)# ip access-group 134 in lag 10 logging enable