This topic describes how IPv4 and IPv6 access control lists (ACLs) operate on Layer 2 physical and bundle main interfaces on the Cisco 8000 Series Router to filter traffic at the data link layer.
Layer 2 ACLs are ethernet access control lists that operate at the data link layer of your network and filter traffic based on MAC addresses, VLAN tags, Ethernet type fields, and user or port-based authentication.
IPv4 and IPv6 ACLs are the Layer 3 access control lists that filter traffic based on IP addresses (IPv4 and IPv6) and other Layer 3 protocol information, such as protocol type, port numbers, and additional flags or control bits in the TCP header.
Feature History Table
|
Feature Name |
Release Information |
Description |
|---|---|---|
|
IPv4 and IPv6 ACLs in Layer 2 |
Release 26.2.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]):* *This feature is supported on:
|
|
IPv4 and IPv6 ACLs in Layer 2 |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
IPv4 and IPv6 ACLs in Layer 2 |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on Cisco 8011-4G24Y4H-I routers. |
|
IPv4 and IPv6 ACLs in Layer 2 |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100, K100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
|
IPv4 and IPv6 ACLs in Layer 2 |
Release 24.2.11 |
You can now configure both IPv4 and IPv6 ACLs on Layer 2 interfaces. This functionality is supported on the physical and bundle main Layer 2 interfaces, enabling Layer 3 ACLs. With this feature, you can implement traffic filtering at Layer 2, effectively preventing undesired traffic from progressing deeper into the network, like using an IPv6 ACL as an IPv6 router advertisement (RA) guard. Previously, IPv6 and IPv4 ACLs were not supported on Layer 2 interface. |
IPv4 and IPv6 ACLs in Layer 2 interface
You can configure both IPv4 and IPv6 ACLs on the physical and bundle main Layer 2 interfaces. Additionally, you can enable Layer 2 (Ethernet) ACLs on the same interface simultaneously.
Advantages of IPv4 and IPv6 ACLs in Layer 2
-
IPv4 and IPv6 ACLs can control which devices can communicate with each other on the same VLAN or between VLANs, thus segmenting and isolating traffic for security purposes.
-
IP-based (IPv4 or IPv6) filtering at Layer 2 helps prevent unauthorized access to network resources.
-
IP address-based ACLs can limit unnecessary broadcast traffic to specific segments of the network, thereby reducing congestion and improving overall network performance.
-
IPv4 and IPv6 ACLs provide protocol-based traffic control, such as TCP, UDP, ICMP, and others.