beautypg.com

Brocade Virtual ADX Security Guide (Supporting ADX v03.1.00) User Manual

Page 63

background image

Brocade Virtual ADX Security Guide

51

53-1003250-01

IPv6 ACL overview

3

Here is another example of commands for configuring an ACL and applying it to an interface.

The first condition permits ICMP traffic from hosts in the 2001:db8:e0bb::x network to hosts in the
2001:3782::x network.

The second condition denies all IPv6 traffic from host 2001:db8:e0ac::2 to host
2001:db8:2383:e0aa:0::24.

The third condition denies all UDP traffic.

The fourth condition permits all packets that are not explicitly denied by the other entries. Without
this entry, the ACL would deny all incoming IPv6 traffic on the ports to which you assigned the ACL.

The following commands apply the ACL netw to the incoming traffic on port 1/2 and to the
incoming traffic on port 4/3.

Here is another example:

The first condition in this ACL denies TCP traffic from the 2001:db8:1570:21::x network to the
2001:db8:1570:22::x network.

The next condition denies UDP packets from any source with source UDP port in ranges 5 to 6 and
whose destination is to the 2001:db8:1570:22::/24 network.

The third condition permits all packets containing source and destination addresses that are not
explicitly denied by the first two. Without this entry, the ACL would deny all incoming IPv6 traffic on
the ports to which you assign the ACL.

A show running-config command displays the following:

A show ipv6 access-list command displays the following:

Virtual ADX(config)#ipv6 access-list netw

Virtual ADX(config-ipv6-access-list-netw)#permit icmp 2001:db8:2383:

e0bb::/64 2001:db8:3782::/64

Virtual ADX(config-ipv6-access-list-netw)#deny ipv6 host 2001:db8:2383:

e0ac::2 host 2001:db8:2383:e0aa:0::24

Virtual ADX(config-ipv6-access-list-netw)#deny udp any any

Virtual ADX(config-ipv6-access-list-netw)#permit ipv6 any any

Virtual ADX(config)#int eth 1/2

Virtual ADX(config-if-1/2)#ipv6 traffic-filter netw in

Virtual ADX(config-if-1/2)#exit

Virtual ADX(config)#int eth 4/3

Virtual ADX(config-if-4/3)#ipv6 traffic-filter netw in

Virtual ADX(config)#write memory

Virtual ADX(config)#ipv6 access-list nextone

Virtual ADX(config-ipv6-access-list rtr)#deny tcp 2001:db8:1570:21::/24

2001:db8:1570:22::/24

Virtual ADX(config-ipv6-access-list rtr)#deny udp any range 5 6 2001:db8:1570:22::

Virtual ADX(config-ipv6-access-list rtr)#permit ipv6 any any

Virtual ADX(config-ipv6-access-list rtr)#write memory

Virtual ADX(config)#show running-config

ipv6 access-list rtr

deny tcp 2001:db8:1570:21::/24 2001:db8:1570:22::/24

deny udp any range 5 6 2001:db8:1570:22::/24

permit ipv6 any any