Default and Implicit IPv6 ACL Action

There are default actions and implicit IPv6 ACL rules.

The default action when no ACLs are configured on an interface is to permit all traffic. However, once you configure an ACL and apply it to an interface, the default action for that interface is to deny all traffic that is not explicitly permitted on the interface.

  • If you want to tightly control access, configure ACLs consisting of permit rules for the access you want to permit. The ACLs implicitly deny all other access.
  • If you want to secure access in environments with many users, you may want to configure ACLs that consist of explicit deny rules, with a permit ipv6 any any rule at the end of each ACL. You must enter permit ipv6 any any as the last statement in the access list if you want to permit IPv6 traffic that was not explicitly denied by the previous statements.

IPv6 ACLs have the following concluding implicit rules:

  • permit icmp any any nd-na: Allows ICMP neighbor discovery acknowledgements.
  • permit icmp any any nd-ns: Allows ICMP neighbor discovery solicitations.
  • deny ipv6 any any: Denies IPv6 traffic.

Note: In an IPv6 ACL, if you do not override the implicit deny ipv6 any any rule, make sure to include rules that permit the IPv6 link-local address and the global unicast address. Otherwise, routing protocols such as OSPF will not work. To view the link-local address, use the show ipv6 interface command.

For example, if you want to deny ICMP neighbor discovery acknowledgment and then permit any remaining IPv6 traffic, enter commands such as the following.

device(config)# ipv6 access-list netw
device(config-ipv6-access-list netw)# permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64
device(config-ipv6-access-list netw)# deny icmp any any nd-na
device(config-ipv6-access-list netw)# permit ipv6 any any

The first permit statement permits ICMP traffic from hosts in the 2001:DB8:e0bb::x network to hosts in the 2001:DB8::x network.

The deny statement denies ICMP neighbor discovery acknowledgments.

The last rule permits all packets that are not explicitly denied by the other rules. Without this rule, the ACL will deny all incoming IPv6 traffic on the ports to which you assigned the ACL.

If you want to deny all neighbor discovery messages, use the statement deny icmp any any in the access list. If you want to permit neighbor discovery but deny all other ICMP traffic, use the permit icmp any any nd-na and permit icmp any any nd-ns statements just before the deny icmp statement as shown in the following example.

device(config)# ipv6 access-list netw
device(config-ipv6-access-list netw)# permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64
device(config-ipv6-access-list netw)# permit icmp any any nd-na
device(config-ipv6-access-list netw)# permit icmp any any nd-ns
device(config-ipv6-access-list netw)# deny icmp any any
device(config-ipv6-access-list netw)# permit ipv6 any any

Note: To configure protection against spurious neighbor discovery (ND) packets employed in Denial of Service (DoS) attacks, refer to Neighbor Discovery (ND)-Packet DoS Attacks .