Default and Implicit IPv6 ACL Action
The default action when no ACLs are configured on an interface is to permit all traffic. However, once you configure an ACL and apply it to an interface, the default action for that interface is to deny all traffic that is not explicitly permitted on the interface.
- If you want to tightly control access, configure ACLs consisting of permit rules for the access you want to permit. The ACLs implicitly deny all other access.
- If you want to secure access in environments with many users, you may want to configure
ACLs that consist of explicit deny rules, with a
permit ipv6 any anyrule at the end of each ACL. You must enterpermit ipv6 any anyas the last statement in the access list if you want to permit IPv6 traffic that was not explicitly denied by the previous statements.
IPv6 ACLs have the following concluding implicit rules:
- permit icmp any any nd-na: Allows ICMP neighbor discovery acknowledgements.
- permit icmp any any nd-ns: Allows ICMP neighbor discovery solicitations.
- deny ipv6 any any: Denies IPv6 traffic.
show ipv6 interface command.
For example, if you want to deny ICMP neighbor discovery acknowledgment and then permit any remaining IPv6 traffic, enter commands such as the following.
device(config)# ipv6 access-list netw device(config-ipv6-access-list netw)# permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64 device(config-ipv6-access-list netw)# deny icmp any any nd-na device(config-ipv6-access-list netw)# permit ipv6 any any
The first permit statement permits ICMP traffic from hosts in the 2001:DB8:e0bb::x network to hosts in the 2001:DB8::x network.
The deny statement denies ICMP neighbor discovery acknowledgments.
The last rule permits all packets that are not explicitly denied by the other rules. Without this rule, the ACL will deny all incoming IPv6 traffic on the ports to which you assigned the ACL.
If you want to deny all neighbor discovery messages, use the statement
deny icmp any any in the access list. If you want to permit neighbor discovery but deny all other ICMP
traffic, use the
permit icmp any any nd-na
and permit icmp any any nd-ns statements just before the
deny icmp statement as shown in the following example.
device(config)# ipv6 access-list netw device(config-ipv6-access-list netw)# permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64 device(config-ipv6-access-list netw)# permit icmp any any nd-na device(config-ipv6-access-list netw)# permit icmp any any nd-ns device(config-ipv6-access-list netw)# deny icmp any any device(config-ipv6-access-list netw)# permit ipv6 any any