Binding IPv6 Source Guard ACLs to Ports
You can bind IPv6 ACLs meant for IPv6
Source Guard (IPv6SG) ports (SG ACL) to a port. IP Source Guard ACLs can then be configured
to allow TCP traffic and all UDP traffic. The following task binds IPv6SG ACL sg-acl1
to
port 1/1/2.
- Enter global configuration mode.
- Configure an Ethernet Interface.
- Enable IPv6SG on the port.
- Bind the IPv6SG ACL to the specified port, applying the ACL to inbound traffic.
The following example defines IPv6 Source Guard ACL sg-acl1.
device# configure terminal device(config)# ipv6 sg-access-list sg-acl1
The following example binds IPv6SG ACL sg-acl1 to port 1/1/2.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# ipv6 source-guard enable device(config-if-e1000/1/1/2)# ipv6 sg-access-group sg1 in
The following example unbinds the IPv6SG ACL.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# no ipv6 sg-access-group sg-acl1
The following example defines IPv6SG ACL sg123 to allow all TCP traffic and all UDP traffic.
device# configure terminal device(config)# ipv6 sg-access-list sg123 device(config-ipv6sgacl-sg123)# permit tcp any any device(config-ipv6sgacl-sg123)# permit udp any any device(config-ipv6sgacl-sg123)# exit device(config)#