Default And Implicit Ipv6 Acl Action - Dell PowerConnect B-RX Configuration Manual

Bigiron rx series configuration guide v02.7.02
Hide thumbs Also See for PowerConnect B-RX:
Table of Contents

Advertisement

47
Configuring an IPv6 ACL
The third condition permits all packets containing source and destination addresses that are not
explicitly denied by the first two. Without this entry, the ACL would deny all incoming IPv6 traffic on
the ports to which you assign the ACL.
A show running-config command displays the following.
BigIron RX(config)# show running-config
ipv6 access-list rtr
deny tcp 2001:1570:21::/24 2001:1570:22::/24
deny udp any range 5 6 2001:1570:22::/24
permit ipv6 any any
A show ipv6 access-list command displays the following.
BigIron RX(config)# sh ipv6 access-list rtr
ipv6 access-list rtr: 3 entries
10: deny tcp 2001:1570:21::/24 2001:1570:22::/24
20: deny udp any range 5 6 2001:1570:22::/24
30: permit ipv6 any any
The following commands apply the ACL "rtr" to the incoming traffic on ports 2/1 and 2/2.
BigIron RX(config)# int eth 2/1
BigIron RX(config-if-2/1)# ipv6 traffic-filter rtr in
BigIron RX(config-if-2/1)# exit
BigIron RX(config)# int eth 2/2
BigIron RX(config-if-2/2)# ipv6 traffic-filter rtr in
BigIron RX(config)# write memory

Default and implicit IPv6 ACL action

The default action when no IPv6 ACLs are configured on an interface is to permit all IPv6 traffic.
However, once you configure an IPv6 ACL and apply it to an interface, the default action for that
interface is to deny all IPv6 traffic that is not explicitly permitted on the interface.
Every IPv6 ACL has the following implicit conditions as its last match conditions.
1. permit icmp any any nd-na – Allows ICMP neighbor discovery acknowledgement.
2. permit icmp any any nd-ns – Allows ICMP neighbor discovery solicitation.
3. deny ipv6 any any – Denies IPv6 traffic. You must enter a permit ipv6 any any as the last
The conditions are applied in the order shown above, with deny ipv6 any any as the last condition
applied.
1188
If you want to tightly control access, configure ACLs consisting of permit entries for the access
you want to permit. The ACLs implicitly deny all other access.
If you want to secure access in environments with many users, you might want to configure
ACLs that consist of explicit deny entries, then add an entry to permit all access to the end of
each ACL. The permit entry permits packets that are not denied by the deny entries.
statement in the access-list if you want to permit IPv6 traffic that were not denied by the
previous statements.
BigIron RX Series Configuration Guide
53-1001810-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Brocade dcx-4sBrocade dcx

Table of Contents