没有合适的资源?快使用搜索试试~ 我知道了~
cisco_ipv6_access-list用法.pdf
需积分: 19 2 下载量 13 浏览量
2011-12-08
16:46:45
上传
评论
收藏 181KB PDF 举报
温馨提示
cisco_ipv6_access-list用法.pdf
资源推荐
资源详情
资源评论
CHAPTER
37-1
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
OL-9639-07
37
Configuring IPv6 ACLs
When the Cisco ME 3400 Ethernet Access switch is running the metro IP access image, you can filter
IP Version 6 (IPv6) traffic by creating IPv6 access control lists (ACLs) and applying them to interfaces
similarly to the way that you create and apply IP Version 4 (IPv4) named ACLs. You can also create and
apply input router ACLs to filter Layer 3 management traffic.
Note To use IPv6, you must configure the dual IPv4 and IPv6 Switch Database Management (SDM) template
on the switch. You select the template by entering the sdm prefer dual-ipv4-and-ipv6 {default |
routing | vlan} global configuration command.
For related information, see these chapters:
• For more information about SDM templates, see Chapter 6, “Configuring SDM Templates.”
• For information about IPv6 on the switch, seeChapter 36, “Configuring IPv6 Unicast Routing.”
• For information about ACLs on the switch, see Chapter 31, “Configuring Network Security with
ACLs.”
Note For complete syntax and usage information for the commands used in this chapter, see the command
reference for this release or the Cisco IOS documentation referenced in the procedures.
This chapter contains these sections:
• Understanding IPv6 ACLs, page 37-2
• Configuring IPv6 ACLs, page 37-3
• Displaying IPv6 ACLs, page 37-8
37-2
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
OL-9639-07
Chapter 37 Configuring IPv6 ACLs
Understanding IPv6 ACLs
Understanding IPv6 ACLs
A switch running the metro IP access image supports two types of IPv6 ACLs:
• IPv6 router ACLs are supported on outbound or inbound traffic on Layer 3 interfaces, which can be
routed ports, switch virtual interfaces (SVIs), or Layer 3 EtherChannels. IPv6 router ACLs apply
only to routed IPv6 packets.
• IPv6 port ACLs are supported only on inbound traffic on Layer 2 interfaces. IPv6 port ACLs are
applied to all IPv6 packets entering the interface.
The switch does not support VLAN ACLs (VLAN maps) for IPv6 traffic.
If you configure unsupported IPv6 ACLs, an error message appears, and the configuration does not take
affect.
Note For more information about IPv4 ACL support on the switch, see Chapter 31, “Configuring Network
Security with ACLs.”
You can apply both IPv4 and IPv6 ACLs to an interface.
As with IPv4 ACLs, IPv6 port ACLs take precedence over router ACLs:
• When an input router ACL and input port ACL exist in an SVI, packets received on ports to which
a port ACL is applied are filtered by the port ACL. Routed IP packets received on other ports are
filtered by the router ACL. Other packets are not filtered.
• When an output router ACL and input port ACL exist in an SVI, packets received on the ports to
which a port ACL is applied are filtered by the port ACL. Outgoing routed IPv6 packets are filtered
by the router ACL. Other packets are not filtered.
Note If any port ACL (IPv4, IPv6, or MAC) is applied to an interface, that port ACL filters packets, and any
router ACLs attached to the SVI of the port VLAN are ignored.
These sections describe some characteristics of IPv6 ACLs on the switch:
• Supported ACL Features, page 37-2
• IPv6 ACL Limitations, page 37-3
Supported ACL Features
IPv6 ACLs on the switch have these characteristics:
• Fragmented frames (the fragments keyword as in IPv4) are supported.
• The same statistics supported in IPv4 are supported for IPv6 ACLs.
• If the switch runs out of hardware space, packets associated with the ACL are forwarded to the CPU,
and the ACLs are applied in software.
• Routed or bridged packets with hop-by-hop options have IPv6 ACLs applied in software.
• Logging is supported for router ACLs, but not for port ACLs.
• The switch supports IPv6 address-matching for a full range of prefix-lengths.
剩余7页未读,继续阅读
资源评论
zyd519
- 粉丝: 0
- 资源: 2
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
最新资源
资源上传下载、课程学习等过程中有任何疑问或建议,欢迎提出宝贵意见哦~我们会及时处理!
点击此处反馈
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功