Creating and Applying an IPv6 ACL
Complete the following steps to create and apply an IPv6 ACL.
- Enter
configure terminalto access global configuration mode. - Enter the
ipv6 access-listcommand followed by a name to create the ACL.An ACL name must begin with an alphabetical character and must contain no more than 47 characters. - For each rule, enter the
denyorpermitcommand, specifying the needed parameters. As an option, you can specify the sequence number followed by a permit or deny statement. Otherwise, the sequence numbers will be added automatically in increments of 10 in the order you enter the statements. - Access an interface on which you need to apply the ACL.
- If needed, enable IPv6 on that interface.
- Apply the ACL to the interface.
The following example creates an IPv6 ACL named netw, with remarks preceding each rule.
device# configure terminal device(config)# ipv6 access-list netw device(config-ipv6-access-list netw)# remark Permits ICMP traffic from 2001:DB8:e0bb::x to 2001:DB8::x. device(config-ipv6-access-list netw)# permit icmp 2001:DB8:e0bb::/64 2001:DB8::/64 device(config-ipv6-access-list netw)# remark Denies traffic from 2001:DB8:e0ac::2 to 2001:DB8:e0aa:0::24. device(config-ipv6-access-list netw)# deny ipv6 host 2001:DB8:e0ac::2 host 2001:DB8:e0aa:0::24 device(config-ipv6-access-list netw)# remark Denies all UDP traffic. device(config-ipv6-access-list netw)# deny udp any any device(config-ipv6-access-list netw)# remark Permits traffic not explicitly denied by the previous rules. device(config-ipv6-access-list netw)# permit ipv6 any any
The following example applies the IPv6 ACL named netw to incoming traffic on ports 1/1/2 and 1/4/3.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000-1/1/2)# ipv6 access-group netw in device(config-if-e1000-1/1/2)# exit device(config)# interface ethernet 1/4/3 device(config-if-e1000-1/4/3)# ipv6 access-group netw in
The following example creates an IPv6 ACL named rtr, with remarks preceding each rule.
device# configure terminal device(config)# ipv6 access-list rtr device(config-ipv6-access-list rtr)# remark Denies TCP traffic from 2001:DB8:21::x to 2001:DB8:22::x. device(config-ipv6-access-list rtr)# deny tcp 2001:DB8:21::/24 2001:DB8:22::/24 device(config-ipv6-access-list rtr)# remark Denies UDP traffic from ports 5 & 6 to 2001:DB8:22::/24. device(config-ipv6-access-list rtr)# deny udp any range 5 6 2001:DB8:22::/24 device(config-ipv6-access-list rtr)# remark Permits traffic not explicitly denied by the previous rules. device(config-ipv6-access-list rtr)# permit ipv6 any any
The following example applies the IPv6 ACL named rtr to incoming traffic on ports 1/2/1 and 1/2/2.
device# configure terminal device(config)# interface ethernet 1/2/1 device(config-if-e1000-1/2/1)# ipv6 access-group rtr in device(config-if-e1000-1/2/1)# exit device(config)# int eth 1/2/2 device(config-if-e1000-1/2/2)# ipv6 access-group rtr in
The following examples show the information
displayed for the IPv6 ACL named rtr in show running-config
ipv6 and show
ipv6 access-list rtr command output.
device# show running-config ipv6 ! ipv6 access-list rtr deny tcp 2001:DB8:21::/24 2001:DB8:22::/24 deny udp any range rje 6 2001:DB8:22::/24 permit ipv6 any any ! device# show ipv6 access-list rtr ipv6 access-list rtr: 3 entries 10: deny tcp 2001:DB8:21::/24 2001:DB8:22::/24 20: deny udp any range rje 6 2001:DB8:22::/24 30: permit ipv6 any any