Cisco ISE can
detect, manage, and secure IPv6 traffic from endpoints.
When an IPv6-enabled endpoint connects to the Cisco ISE network, it communicates with the Network Access Device (NAD) over
an IPv6 network. The NAD conveys the accounting and profiling information from the endpoint (including IPv6 values) to Cisco
ISE over an IPv4 network. You can configure authorization profiles and policies in Cisco ISE using the IPv6 attributes in
your rule conditions to process such requests from IPv6-enabled endpoints and ensure that the endpoint is compliant.
You can use wildcard characters in IPv6 prefix and IPv6 interface values. For example: 2001:db8:1234::/48.
Supported IPv6
address formats include:
-
Full notation:
Eight groups of four hexadecimal digits separated by colons. For example,
2001:0db8:85a3:0000:0000:8a2e:0370:7334
-
Shortened
notation: Exclude leading zeros in a group; replace groups of zeros with two
consecutive colons. For example: 2001:db8:85a3::8a2e:370:7334
-
Dotted-quad
notation (IPv4-mapped and IPv4 compatible-IPv6 addresses): For example,
::ffff:192.0.2.128
Supported IPv6
attributes include:
The following table lists Supported Cisco Attribute-Value pairs and their equivalent IETF attributes:
Cisco
Attribute-Value Pairs
|
IETF
Attributes
|
ipv6:addrv6=<ipv6 address>
|
Framed-ipv6-Address
|
ipv6:stateful-ipv6-address-pool=<name>
|
Stateful-IPv6-Address-Pool
|
ipv6:delegated-ipv6-pool=<name>
|
Delegated-IPv6-Prefix-Pool
|
ipv6:ipv6-dns-servers-addr=<ipv6 address>
|
DNS-Server-IPv6-Address
|
The RADIUS Live Logs page, RADIUS Authentication report, RADIUS Accounting report, Current Active Session report, RADIUS Error
report, Misconfigured NAS report, EPS Audit report, and Misconfigured Supplicant report support IPv6 addresses. You can view the details about these sessions from the RADIUS
Live Logs page or from any of these reports. You can filter the records by IPv4, IPv6, or MAC addresses.
 Note |
If you connect
an Android device to an IPv6 enabled DHCPv6 network, it receives only the
link-local IPv6 address from the DHCP server. Hence, global IPv6 address is not
displayed in the Live Logs and in the Endpoints page ().
|
The following
procedure describes how to configure IPv6 attributes in authorization policies.