ipv6 access-list
The IPv6 ACL is not configured.
Global configuration mode
An ACL name must be unique among IPv6 and IPv4 ACLs.
The following points apply to naming ACLs:
- An ACL name must begin with an alphabetical character followed by alphanumeric characters.
- The maximum length of an ACL name is 47 characters.
- An ACL name cannot contain special characters such as a double quote (").
- The ACL name cannot be 'test'.
The
no form of the command removes the configured IPv6 ACL.
In IPv6 access-list permit and deny statements, the following protocols can be matched:
- a numbered IPv6 protocol (decimal values 0 through 255)
- ahp - Authentication Header Protocol
- esp - Encapsulating Security Payload
- icmp - Internet Control Message Protocol
- ipv6 - Internet Protocol version 6
- sctp - Stream Control Transmission Protocol
- tcp - Transmission Control Protocol
- udp - User Datagram Protocol
In IPv6 access-lists, the following TCP/UDP application port names are allowed, in addition to any application-specific port number in decimal format:
The following example configures an IPv6 ACL named "acl1" to permit all UDP traffic.
device# configure terminal device(config)# ipv6 access-list acl1 device(config-ipv6-access-list acl1)# permit udp any any
The following example creates an ACL that, when applied, blocks web access (traffic from port 80) from a specific source IPv6 address to the destination address for a particular web host.
device# configure terminal device(config)# ipv6 access-list acltcp device(config-ipv6-access-list acltcp)# deny tcp 2000:DB8:e0bb::/64 eq 80 1000:D01:c011::/64 device(config-ipv6-access-list acltcp)# permit ipv6 any any
The following example creates and applies an IPv6 access list that enables accounting, denies IPv6 traffic from a particular host, and allows all other IPv6 traffic.
device# configure terminal device(config)# ipv6 access-list aclv6stats device(config-ipv6-access-list aclv6stats)# enable accounting device(config-ipv6-access-list aclv6stats)# deny ipv6 2001:DB8:e0bb::/64 any log device(config-ipv6-access-list aclv6stats)# permit ipv6 any any device(config-ipv6-access-list aclv6stats)# interface ethernet 1/3/1 device((config-if-e1000-1/3/1)# ipv6 access-group aclv6stats in logging enable