Chapter 35 Configuring IPv6 ACLs

Configuring IPv6 ACLs

 

Command

Purpose

Step 3b

 

 

{deny permit} tcp

(Optional) Define a TCP access list and the access conditions.

 

{source-ipv6-prefix/prefix-length

Enter tcp for Transmission Control Protocol. The parameters are the same as

 

any host source-ipv6-address}

those described in Step 3a, with these additional optional parameters:

 

[operator [port-number]]

 

ackAcknowledgment bit set.

 

{destination-ipv6-

 

prefix/prefix-length any host

establishedAn established connection. A match occurs if the TCP

 

destination-ipv6-address}

 

datagram has the ACK or RST bits set.

 

[operator [port-number]] [ack]

 

fin—Finished bit set; no more data from sender.

 

[dscp value] [established] [fin]

 

 

 

[log] [log-input] [neq {port

neq {port protocol}Matches only packets that are not on a given port

 

protocol}] [psh] [range {port

number.

 

protocol}] [rst] [routing]

psh—Push function bit set.

 

[sequence value] [syn]

 

range {port protocol}—Matches only packets in the port number range.

 

[time-range name] [urg]

 

 

rst—Reset bit set.

 

 

syn—Synchronize bit set.

 

 

urgUrgent pointer bit set.

Step 3c

 

 

{deny permit} udp

(Optional) Define a UDP access list and the access conditions.

 

{source-ipv6-prefix/prefix-length

Enter udp for the User Datagram Protocol. The UDP parameters are the same

 

any host source-ipv6-address}

as those described for TCP, except that the [operator [port]] port number or

 

[operator [port-number]]

 

name must be a UDP port number or name, and the established parameter is

 

{destination-ipv6-prefix/prefix-len

 

not valid for UDP.

 

gth any host

 

 

destination-ipv6-address}

 

 

[operator [port-number]] [dscp

 

 

value] [log] [log-input] [neq {port

 

 

protocol}] [range {port

 

 

protocol}] [routing] [sequence

 

 

value] [time-range name]

 

Step 3d

 

 

{deny permit} icmp

(Optional) Define an ICMP access list and the access conditions.

 

{source-ipv6-prefix/prefix-length

Enter icmp for Internet Control Message Protocol. The ICMP parameters are

 

any host source-ipv6-address}

the same as those described for most IP protocols in Step 3a, with the addition

 

[operator [port-number]]

 

of the ICMP message type and code parameters. These optional keywords have

 

{destination-ipv6-prefix/prefix-len

 

these meanings:

 

gth any host

icmp-type—Enter to filter by ICMP message type, a number from 0 to 255.

 

destination-ipv6-address}

 

[operator [port-number]]

icmp-code—Enter to filter ICMP packets that are filtered by the ICMP

 

[icmp-type [icmp-code]

 

message code type, a number from 0 to 255.

 

icmp-message] [dscp value] [log]

 

icmp-message—Enter to filter ICMP packets by the ICMP message type

 

[log-input] [routing] [sequence

 

name or the ICMP message type and code name. To see a list of ICMP

 

value] [time-range name]

 

message type names and code names, use the ? key or see command

 

 

 

 

reference for this release.

Step 4

 

 

end

Return to privileged EXEC mode.

Step 5

 

 

show ipv6 access-list

Verify the access list configuration.

Step 6

 

 

copy running-config

(Optional) Save your entries in the configuration file.

 

startup-config

 

 

 

 

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

 

OL-9775-02

35-7

 

 

 

Page 747
Image 747
Cisco Systems 3750E manual 35-7