Supported Acl Features - Cisco IE-4000 Software Configuration Manual

Industrial ethernet switch
Hide thumbs Also See for IE-4000:
Table of Contents

Advertisement

Configuring IPv6 ACLs
Prerequisites

Supported ACL Features

IPv6 ACLs on the switch have these characteristics:
Fragmented frames (the fragments keyword as in IPv4) are supported.
The same statistics supported in IPv4 are supported for IPv6 ACLs.
If the switch runs out of hardware space, packets associated with the ACL are forwarded to the CPU, and the
software applies the ACLs.
Routed or bridged packets with hop-by-hop options have IPv6 ACLs applied in software.
Logging is supported for router ACLs, but not for port ACLs.
The switch supports IPv6 address-matching for a full range of prefix-lengths.
Note:
For items not supported for IPv6 ACLS, see
Prerequisites
Be sure to review
Guidelines and Limitations, page 782
section before configuring a feature.
Guidelines and Limitations
ACLs for IPv6 Traffic Not Supported
The switch does not support VLAN ACLs (VLAN maps) for IPv6 traffic.
The switch does not apply MAC-based ACLs on IPv6 frames.
You cannot apply IPv6 port ACLs to Layer 2 EtherChannels.
The switch does not support output port ACLs.
Cisco IOS IPv6 ACLs Functions Not Supported
The switch does not support matching on these keywords: flowlabel, routing header, and
undetermined-transport.
The switch does not support reflexive ACLs (the reflect keyword).
Access Control Entry (ACE) and ACLs
When you apply an ACL to an interface and you attempt to add an access control entry (ACE) with an unsupported
keyword, the switch does not allow the ACE to be added to the attached ACL.
Named ACLs
IPv6 supports only named ACLs.
IPv6 ACLs Interactions With Other Switches or Features
When you configure an IPv6 router ACL to deny a packet, the software does not route the packet. Instead, the
software forwards a copy of the packet to the Internet Control Message Protocol (ICMP) queue to generate an ICMP
unreachable message for the frame.
If a bridged frame is to be dropped due to a port ACL, the frame is not bridged.
Guidelines and Limitations, page
and the Before You Begin section within each configuration
782
782.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ie-5000Ie-4010

Table of Contents