ipv6 sg-access-list

Creates an IPv6 Source Guide (IPSGv6) ACL and enters IPv6 SG access list configuration mode.
Syntax
ipv6 sg-access-list acl-name in
no ipv6 sg-access-list acl-name in
Command Default

An IPSGv6 ACL is not configured.

Parameters
acl-name
Specifies the ACL to be defined.
Modes

Global configuration mode

Usage Guidelines

The following syntax is used to create ipv6 sg-access-list filter statements:

device(config-sgaclv6-name)# permit { protocol any any }

The command supports only wildcard IP host and IP network addresses ("any any").

The command supports permit actions for the following protocols:

  • ipv6
  • tcp
  • udp

The command does not support deny actions, logging, mirroring, or DSCP.

The sg-aclv6 command must be configured globally, and the ipv6 source-guard enable command configured for the interface, before an IPSGv6 ACL can be bound to it.

The no form of the command deletes the ACL.

Examples

The following example, enters IPv6 SG access list configuration mode and then defines IPv6 Source Guard ACL sg123 to allow all TCP traffic and all UDP traffic.

device# configure terminal
device(config)# ipv6 sg-access-list sg123
device(config-ipv6sgacl-sg123)# permit tcp any any
device(config-ipv6sgacl-sg123)# permit udp any any

The following example binds IPv6 Source Guard ACL sg-acl1 to port 1/1/2.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# ipv6 source-guard enable
device(config-if-e1000/1/1/2)# ipv6 sg-access-group sg-acl1 in

The following example unbinds the ACL.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no ipv6 sg-access-group sg-acl1 in
History
Release version Command history
10.0.20b_cd1 This command was introduced.