1180 BigIron RX Series Configuration Guide53-1001986-01Configuring an IPv6 ACL47The following commands apply the ACL “rtr” to the incoming traffic on ports 2/1 and 2/2.Default and implicit IPv6 ACL actionThe default action when no IPv6 ACLs are configured on an interface is to permit all IPv6 traffic.However, once you configure an IPv6 ACL and apply it to an interface, the default action for thatinterface is to deny all IPv6 traffic that is not explicitly permitted on the interface.• If you want to tightly control access, configure ACLs consisting of permit entries for the accessyou want to permit. The ACLs implicitly deny all other access.• If you want to secure access in environments with many users, you might want to configureACLs that consist of explicit deny entries, then add an entry to permit all access to the end ofeach ACL. The permit entry permits packets that are not denied by the deny entries.Every IPv6 ACL has the following implicit conditions as its last match conditions.1. permit icmp any any nd-na – Allows ICMP neighbor discovery acknowledgement.2. permit icmp any any nd-ns – Allows ICMP neighbor discovery solicitation.3. deny ipv6 any any – Denies IPv6 traffic. You must enter a permit ipv6 any any as the laststatement in the access-list if you want to permit IPv6 traffic that were not denied by theprevious statements.The conditions are applied in the order shown above, with deny ipv6 any any as the last conditionapplied.For example, if you want to deny ICMP neighbor discovery acknowledgement, then permit anyremaining IPv6 traffic, enter commands such as the following.The first permit statement permits ICMP traffic from hosts in the 2000:2383:e0bb::x network tohosts in the 2001:3782::x network.The deny statement denies ICMP neighbor discovery acknowledgement.The last entry permits all packets that are not explicitly denied by the other entries. Without thisentry, the ACL will deny all incoming IPv6 traffic on the ports to which you assigned the ACL.BigIron RX(config)# sh ipv6 access-list rtripv6 access-list rtr: 3 entries10: deny tcp 2001:1570:21::/24 2001:1570:22::/2420: deny udp any range 5 6 2001:1570:22::/2430: permit ipv6 any anyBigIron RX(config)# int eth 2/1BigIron RX(config-if-2/1)# ipv6 traffic-filter rtr inBigIron RX(config-if-2/1)# exitBigIron RX(config)# int eth 2/2BigIron RX(config-if-2/2)# ipv6 traffic-filter rtr inBigIron RX(config)# write memoryBigIron RX(config)# ipv6 access-list netwBigIron RX(config-ipv6-access-list-netw)# permit icmp 2000:2383:e0bb::/642001:3782::/64BigIron RX(config-ipv6-access-list-netw)# deny icmp any any nd-naBigIron RX(config-ipv6-access-list-netw)# permit ipv6 any any