11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

deny (IPv6 access-list configuration)Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sUsage GuidelinesThe deny (IPv6 access-list configuration mode) comm<strong>and</strong> is similar to the deny (IPv4 access-listconfiguration mode) comm<strong>and</strong>, but it is IPv6-specific.Use the deny (IPv6) comm<strong>and</strong> after the ipv6 access-list comm<strong>and</strong> to enter IPv6 access list configurationmode <strong>and</strong> to define the conditions under which a packet passes the access list.Specifying IPv6 for the protocol argument matches against the IPv6 header of the packet.By default, the first statement in an access list is number 10, <strong>and</strong> the subsequent statements are numberedin increments of 10.You can add permit, deny, or remark statements to an existing access list without re-entering the entirelist. To add a new statement anywhere other than at the end of the list, create a new statement with anappropriate entry number between two existing entry numbers to show where it belongs.NoteEvery IPv6 ACL has implicit permit icmp any any nd-na, permit icmp any any nd-ns, <strong>and</strong> deny ipv6any any statements as its last match conditions. The two permit conditions allow ICMPv6 neighbordiscovery. To disallow ICMPv6 neighbor discovery <strong>and</strong> to deny icmp any any nd-na or icmp any anynd-ns, there must be an explicit deny entry in the ACL. For the three implicit statements to take effect,an IPv6 ACL must contain at least one entry.The IPv6 neighbor discovery process uses the IPv6 network layer service. Therefore, by default, IPv6ACLs implicitly allow IPv6 neighbor discovery packets to be sent <strong>and</strong> received on an interface. In IPv4,the Address Resolution Protocol (ARP), which is equivalent to the IPv6 neighbor discovery process, usesa separate data-link layer protocol. Therefore, by default, IPv4 ACLs implicitly allow ARP packets tobe sent <strong>and</strong> received on an interface.Both the source-ipv6-prefix/prefix-length <strong>and</strong> destination-ipv6-prefix/prefix-length arguments are usedfor traffic filtering. (The source prefix filters traffic based upon the traffic source; the destination prefixfilters traffic based upon the traffic destination.)The switch supports IPv6 address matching for a full range of prefix-lengths.The fragments keyword is an option only if the protocol is ipv6 <strong>and</strong> the operator [port-number]arguments are not specified.This is a list of ICMP message names:beyond-scopeecho-replyheadermld-querymld-reportnd-nsno-adminpacket-too-bigparameter-problemreassembly-timeoutrenum-resultrouter-advertisementdestination-unreachableecho-requesthop-limitmld-reductionnd-nanext-headerno-routeparameter-optionport-unreachablerenum-comm<strong>and</strong>renum-seq-numberrouter-renumbering2-134<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> ReferenceOL-9776-08

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!