IPv6 ACL Configuration Notes
Consider the following configuration guidelines for IPv6 ACLs:
- IPv4 source guard and IPv6 ACLs are supported together on the same device, as long as they are not configured on the same port or VLAN.
- IPv6 ACLs are supported on tagged ports.
- IPv6 ingress and egress ACLs can be bound to an interface or VLAN without
ipv6 enablebeing configured on the physical or virtual interface. - IPv6 ACLs cannot be used with GRE.
- IPv6 ACLs cannot be employed to implement a user-based ACL scheme.
- On interfaces that have IPv6 ACLs applied on outbound packets, the following features are not supported:
- IPv6 ACLs with traffic policies are not downloadable on IEEE 802.1X and MAC authentication-enabled ports.
- It is not possible to configure conflicting ACL
filters. When configuring an ACL filter, if the filter parameters match with an
existing filter but the action does not match, the following error message is
displayed:
Error: ACL operation failed for ACL ipv6-test1 since following conflicting filter entry already exists. Please use explicit sequence number to override this error.