ipv6 access-list

Creates an IPv6 access control list (ACL) and enters IPv6 access-list configuration sub-mode.
Syntax
ipv6 access-list { acl-name }
no ipv6 access-list { acl-name }
Command Default

The IPv6 ACL is not configured.

Parameters
acl-name
Specifies the ACL name.
Modes

Global configuration mode

Usage Guidelines

An ACL name must be unique among IPv6 and IPv4 ACLs.

The following points apply to naming ACLs:

  • An ACL name must begin with an alphabetical character followed by alphanumeric characters.
  • The maximum length of an ACL name is 47 characters.
  • An ACL name cannot contain special characters such as a double quote (").
  • The ACL name cannot be 'test'.

The no form of the command removes the configured IPv6 ACL.

In IPv6 access-list permit and deny statements, the following protocols can be matched:

  • a numbered IPv6 protocol (decimal values 0 through 255)
  • ahp - Authentication Header Protocol
  • esp - Encapsulating Security Payload
  • icmp - Internet Control Message Protocol
  • ipv6 - Internet Protocol version 6
  • sctp - Stream Control Transmission Protocol
  • tcp - Transmission Control Protocol
  • udp - User Datagram Protocol

In IPv6 access-lists, the following TCP/UDP application port names are allowed, in addition to any application-specific port number in decimal format:

  • ftp-data
  • ftp
  • ssh
  • telnet
  • smtp
  • dns
  • http
  • gppitnp
  • pop2
  • pop3
  • sftp
  • sqlserv
  • bgp
  • ldap
  • ssl

Examples

The following example configures an IPv6 ACL named "acl1" to permit all UDP traffic.

device# configure terminal
device(config)# ipv6 access-list acl1
device(config-ipv6-access-list acl1)# permit udp any any

The following example creates an ACL that, when applied, blocks web access (traffic from port 80) from a specific source IPv6 address to the destination address for a particular web host.

device# configure terminal
device(config)# ipv6 access-list acltcp
device(config-ipv6-access-list acltcp)# deny tcp 2000:DB8:e0bb::/64 eq 80 1000:D01:c011::/64
device(config-ipv6-access-list acltcp)# permit ipv6 any any

The following example creates and applies an IPv6 access list that enables accounting, denies IPv6 traffic from a particular host, and allows all other IPv6 traffic.

device# configure terminal
device(config)# ipv6 access-list aclv6stats
device(config-ipv6-access-list aclv6stats)# enable accounting
device(config-ipv6-access-list aclv6stats)# deny ipv6 2001:DB8:e0bb::/64 any log
device(config-ipv6-access-list aclv6stats)# permit ipv6 any any
device(config-ipv6-access-list aclv6stats)# interface ethernet 1/3/1
device((config-if-e1000-1/3/1)# ipv6 access-group aclv6stats in logging enable
History
Release version Command history
08.0.95 This command was modified to allow the enable accounting option.