Configuring an IPv6 PBR Policy with the NULL0 Interface as the Next Hop

Perform the following steps to configure an IPv6 PBR to set the NULL0 interface as the next hop in the route map.

The NULL0 interface does not forward traffic or receive traffic. Setting the next hop as the NULL0 interface drops the packet instead of forwarding the packet.

  1. Enter global configuration mode.
    device# configure terminal
  2. Define the required IPv6 ACLs to be added to the route map.
    device(config)# ipv6 access-list acl1
  3. Define a permit clause with an IPv6 address.
    device(config-ipv6-access-list acl1)# permit ipv6 2001:db8:85a3:0:0:8a2e:370:7334 any
  4. Define a deny clause.
    device(config-ipv6-access-list acl1)# deny ipv6 any any
  5. Return to global configuration mode.
    device(config-ipv6-access-list acl1)# exit
  6. Enter the route-map command to define the route and specify the match criteria and the resulting action if all the match clauses are met.
    device(config)# route-map null-route permit acl1
  7. Add IPv6 ACLs to match the IP address that is permitted by the ACL.
    device(config-routemap null-route)# match ipv6 address acl1
  8. Set the next hop as the NULL0 interface to send the traffic to the null interface, and this action will drop the packet instead of forwarding it.
    device(config-routemap null-route)# set interface null0
  9. Enter the exit command to return to global configuration mode.
    device(config-routemap null-route)# exit
  10. Enter configuration mode on the interface where you want to enable PBR by applying the route map.
    device(config)# interface ethernet 1/1/3
    IPv6 PBR can be enabled globally by which the route map is applied to all interfaces using the ip policy route-map command from global configuration mode.
  11. Enable PBR on the interface and specify the route map to be used.
    device(config-if-e1000-1/1/3)# ipv6 policy route-map null-route

The following example shows the configuration steps to configure a PBR policy to send all IPv6 traffic from 2001:db8:85a3:0:0:8a2e:370:7334 to the NULL0 interface, thus dropping the traffic instead of forwarding it.

device# configure terminal
device(config)# ipv6 access-list acl1
device(config-ipv6-access-list acl1)# permit ipv6 2001:db8:85a3:0:0:8a2e:370:7334 any
device(config-ipv6-access-list acl1)# deny ipv6 any any
device(config-ipv6-access-list acl1)# exit
device(config)# route-map null-route permit acl1
device(config-routemap null-route)# match ip address acl1
device(config-routemap null-route)# set interface null0
device(config-routemap null-route)# exit
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# ipv6 policy route-map null-route
device(config-if-e1000-1/1/3)# end