Binding IPv6 Source Guard ACLs to Ports

You can bind IPv6 ACLs meant for IPv6 Source Guard (IPv6SG) ports (SG ACL) to a port. IP Source Guard ACLs can then be configured to allow TCP traffic and all UDP traffic. The following task binds IPv6SG ACL sg-acl1 to port 1/1/2.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure an Ethernet Interface.
    device(config)# interface ethernet 1/1/2
    
  3. Enable IPv6SG on the port.
    device(config-if-e1000/1/1/2)# ipv6 source-guard enable
  4. Bind the IPv6SG ACL to the specified port, applying the ACL to inbound traffic.
    device(config-if-e1000/1/1/2)# ipv6 sg-access-group sg1 in

The following example defines IPv6 Source Guard ACL sg-acl1.

device# configure terminal
device(config)# ipv6 sg-access-list sg-acl1

The following example binds IPv6SG ACL sg-acl1 to port 1/1/2.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# ipv6 source-guard enable
device(config-if-e1000/1/1/2)# ipv6 sg-access-group sg1 in

The following example unbinds the IPv6SG ACL.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no ipv6 sg-access-group sg-acl1

The following example defines IPv6SG ACL sg123 to allow all TCP traffic and all UDP traffic.

device# configure terminal
device(config)# ipv6 sg-access-list sg123
device(config-ipv6sgacl-sg123)# permit tcp any any
device(config-ipv6sgacl-sg123)# permit udp any any
device(config-ipv6sgacl-sg123)# exit
device(config)#