This topic describes how ingress IPv6 hybrid ACLs with compression level 2 can filter packets on the basis of IPv6 extension headers on the Cisco 8000 Series Router.
As illustrated in the figure, an IPv6 packet may carry zero, one, or more extension headers, each identified by the Next Header field of the preceding header. To configure ingress hybrid ACLs with ACEs that permit or deny packets on the basis of IPv6 extension headers, the IPv6 extension headers must be set immediately after the base IPv6 header as shown in the figure.
Therefore, you can filter ingress IPv6 packets through hybrid ACLs with compression level 2 on the basis of IPv6 extension headers set in them.
You can filter ingress IPv6 packets having hop-by-hop extension headers through regular ACLs or through hybrid ACLs with compression level 2.
Feature History Table
|
Feature Name |
Release Information |
Description |
|---|---|---|
| IPv6 Extension Headers in Hybrid ACLs |
Release 26.2.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]):* *This feature is supported on Cisco 88-LC1-48Y8H-EM line cards. |
| IPv6 Extension Headers in Hybrid ACLs |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
| IPv6 Extension Headers in Hybrid ACLs |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*) This feature is supported on:
|
| IPv6 Extension Headers in Hybrid ACLs |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
| IPv6 Extension Headers in Hybrid ACLs |
Release 7.3.15 |
You can configure ingress IPv6 hybrid ACLs with compression level 2 to permit or deny packets on the basis of IPv6 extension headers set in them. IPv6 extension headers include routing headers, authentication headers, and destination option headers. These extension headers contain information that is used by network devices (routers and switches) to route or process an ingress IPv6 packet. The ipv6 access-group command is updated. |