Command Mode
Extended IPv6 ACL
Command Usage
◆
Example
This example accepts any incoming packets if the destination address is
2009:DB9:2229::79/8.
Related Commands
access-list ipv6 (342)
Time Range (177)
ipv6 access-group
This command binds a port to an IPv6 ACL. Use the no form to remove the port.
Syntax
Default Setting
None
Command Mode
Interface Configuration (Ethernet)
Command Usage
◆
◆
All new rules are appended to the end of the list.
Console(config-ext-ipv6-acl)#permit 2009:DB9:2229::79/8
Console(config-ext-ipv6-acl)#
ipv6 access-group acl-name {in | out} [time-range time-range-name]
[counter]
no ipv6 access-group acl-name {in | out}
acl-name – Name of the ACL. (Maximum length: 16 characters)
in – Indicates that this list applies to ingress packets.
out – Indicates that this list applies to egress packets.
time-range-name - Name of the time range. (Range: 1-32 characters)
counter – Enables counter for ACL statistics.
A port can only be bound to one ACL.
If a port is already bound to an ACL and you bind it to a different ACL, the
switch will replace the old binding with the new one.
– 345 –
Chapter 9
| Access Control Lists
IPv6 ACLs