Reference Guide
deny tcp – assigns a deny filter for TCP traffic.
ipv6 access-group
Assign an IPv6 access-group to an interface.
C-Series, E-Series, S-Series
Syntax
ipv6 access-group access-list-name {in | out} [implicit-permit]
[vlan range]
To delete an IPv6 access-group configuration, use the no ipv6 access-group
access-list-name {in} [implicit-permit] [vlan range] command.
Parameters
access-list-name
Enter the name of a configured access list, up to 140 characters.
in | out Enter either the keyword in or out to apply the IPv6 ACL to incoming
traffic (ingress) or outgoing traffic (egress).
implicit-permit (OPTIONAL) Enter the keywords implicit-permit to change the
default action of the IPv6 ACL from implicit-deny to implicit-permit
(that is, if the traffic does not match the filters in the IPv6 ACL, the
traffic is permitted instead of dropped).
vlan
range
(OPTIONAL) Enter the keyword vlan followed by the VLAN range in
a comma separated format. The range is 1 to 4094.
Defaults Disabled.
Command Modes INTERFACE
Command History
Version 8.4.2.1 Introduced on the S-Series.
Version 7.8.1.0 Introduced on the C-Series. Increased the name string to accept up
to 140 characters. Prior to version 7.8.1.0, names are up to 16
characters long.
Version 7.4.1.0 Introduced on the E-Series TeraScale.
Usage
Information
You can assign an IPv6 access group to a physical, LAG, or VLAN interface context.
Example
FTOS(conf-if-gi-9/0)#ipv6 access-group AclList1 in implicit-
permit vlan 10-20
FTOS(conf-if-gi-9/0)#show config
!
interface GigabitEthernet 9/0
no ip address
ipv6 access-group AclList1 in implicit-permit Vlan 10-20
no shutdown
FTOSconf-if-gi-9/0)#
923










