Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPV6 based ACL's (Cisco 3560 switch)

Hi there,

I am currently using a C3560-24TS running c3560-ipbase-mz.122-25.SEE2 for a top of rack access switch.

From what I can see, to use ipv6 based access-lists I would need to upgrade to the advanced IP services image.

I was wondering if any one could suggest a ninja like way to enforce the dropping of ipv6 packets without having to change the image running on the switch?

This is to prevent hosts sharing the same switch from making ipv6 based comms.

Best Regards

D

2 REPLIES

Re: IPV6 based ACL's (Cisco 3560 switch)

Hi there,

I am currently using a C3560-24TS running c3560-ipbase-mz.122-25.SEE2 for a top of rack access switch.

From what I can see, to use ipv6 based access-lists I would need to upgrade to the advanced IP services image.

I was wondering if any one could suggest a ninja like way to enforce the dropping of ipv6 packets without having to change the image running on the switch?

This is to prevent hosts sharing the same switch from making ipv6 based comms.

Best Regards

D

Hi D,

IOS are the codes in the switches which can perform the commands which are designed in those IOS,If ipv6 needs advanced ip services image you need to have that image in order to use ip v6 acl in the switch because ip services image is not build to understand the ip v6 commands.

Hope to Help !!

Ganesh.H

New Member

Re: IPV6 based ACL's (Cisco 3560 switch)

A colleague suggsted possibly doing this on the ethernet header type instead :

mac access-list extended IPV6_PACKET

permit any any 0x86dd 0x0

vlan access-map BLOCK_IPV6 10

match mac address IPV6_PACKET

action drop

vlan access-map BLOCK_IPV6 20

action forward

vlan filter BLOCK_IPV6 vlan-list <...>

Does anyone have any experience in using the above before I have a go in a test environment?

Cheers

484
Views
0
Helpful
2
Replies