Creating and Applying an IPv6 ACL

Before an IPv6 ACL can be applied to an interface or a VLAN, it must first be created.

Complete the following steps to create and apply an IPv6 ACL.

  1. Enter configure terminal to access global configuration mode.
    device# configure terminal
    
  2. Enter the ipv6 access-list command followed by a name to create the ACL.
    An ACL name must begin with an alphabetical character and must contain no more than 47 characters.
    device(config)# ipv6 access-list ipv6_test
    
  3. For each rule, enter the deny or permit command, specifying the needed parameters. As an option, you can specify the sequence number followed by a permit or deny statement. Otherwise, the sequence numbers will be added automatically in increments of 10 in the order you enter the statements.
    device(config-ipv6-access-list ipv6_test)# deny tcp host 2001:DB8:e0bb::2 any eq telnet
    device(config-ipv6-access-list ipv6_test)# permit ipv6 any any
    
  4. Access an interface on which you need to apply the ACL.
    device(config-ipv6-access-list ipv6_test)# exit
    device(config)# interface ethernet 1/1/1
    
  5. If needed, enable IPv6 on that interface.
    device(config-if-e1000-1/1/1)# ipv6 enable
    
  6. Apply the ACL to the interface.
    device(config-if-e1000-1/1/1)# ipv6 access-group ipv6_test in
    

The following example creates an IPv6 ACL named netw, with remarks preceding each rule.

device# configure terminal
device(config)# ipv6 access-list netw

device(config-ipv6-access-list netw)# remark Permits ICMP traffic from 2001:DB8:e0bb::x to 2001:DB8::x.
device(config-ipv6-access-list netw)# permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64

device(config-ipv6-access-list netw)# remark Denies traffic from 2001:DB8:e0ac::2 to 2001:DB8:e0aa:0::24.
device(config-ipv6-access-list netw)# deny ipv6 host 2001:DB8:e0ac::2 host 2001:DB8:e0aa:0::24

device(config-ipv6-access-list netw)# remark Denies all UDP traffic.
device(config-ipv6-access-list netw)# deny udp any any

device(config-ipv6-access-list netw)# remark Permits traffic not explicitly denied by the previous rules.
device(config-ipv6-access-list netw)# permit ipv6 any any

The following example applies the IPv6 ACL named netw to incoming traffic on ports 1/1/2 and 1/4/3.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000-1/1/2)# ipv6 access-group netw in
device(config-if-e1000-1/1/2)# exit
device(config)# interface ethernet 1/4/3
device(config-if-e1000-1/4/3)# ipv6 access-group netw in

The following example creates an IPv6 ACL named rtr, with remarks preceding each rule.

device# configure terminal
device(config)# ipv6 access-list rtr

device(config-ipv6-access-list rtr)# remark Denies TCP traffic from 2001:DB8:21::x to 2001:DB8:22::x.
device(config-ipv6-access-list rtr)# deny tcp 2001:DB8:21::/24 2001:DB8:22::/24

device(config-ipv6-access-list rtr)# remark Denies UDP traffic from ports 5 & 6 to 2001:DB8:22::/24.
device(config-ipv6-access-list rtr)# deny udp any range 5 6 2001:DB8:22::/24

device(config-ipv6-access-list rtr)# remark Permits traffic not explicitly denied by the previous rules.
device(config-ipv6-access-list rtr)# permit ipv6 any any

The following example applies the IPv6 ACL named rtr to incoming traffic on ports 1/2/1 and 1/2/2.

device# configure terminal
device(config)# interface ethernet 1/2/1
device(config-if-e1000-1/2/1)# ipv6 access-group rtr in
device(config-if-e1000-1/2/1)# exit
device(config)# int eth 1/2/2
device(config-if-e1000-1/2/2)# ipv6 access-group rtr in

The following examples show the information displayed for the IPv6 ACL named rtr in show running-config ipv6 and show ipv6 access-list rtr command output.

device# show running-config ipv6
!
ipv6 access-list rtr
deny tcp 2001:DB8:21::/24 2001:DB8:22::/24
deny udp any range rje 6 2001:DB8:22::/24
permit ipv6 any any
!

device# show ipv6 access-list rtr
ipv6 access-list rtr: 3 entries
10: deny tcp 2001:DB8:21::/24 2001:DB8:22::/24
20: deny udp any range rje 6 2001:DB8:22::/24
30: permit ipv6 any any