- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- Comware Based
- >
- ACL to completely block IPv6 on 5700 FF
-
-
Categories
- Topics
- Hybrid IT with Cloud
- Mobile & IoT
- IT for Data & Analytics
- Transformation
- Strategy and Technology
- Products
- Cloud
- Integrated Systems
- Networking
- Servers and Operating Systems
- Services
- Storage
- Company
- Events
- Partner Solutions and Certifications
- Welcome
- Welcome
- Announcements
- Tips and Tricks
- Feedback
-
Blogs
- Alliances
- Around the Storage Block
- Behind the scenes @ Labs
- Converged Data Center Infrastructure
- Digital Transformation
- Grounded in the Cloud
- HPE Careers
- HPE Storage Tech Insiders
- Infrastructure Insights
- Inspiring Progress
- Internet of Things (IoT)
- My Learning Certification
- Networking
- OEM Solutions
- Servers: The Right Compute
- Telecom IQ
- Transforming IT
-
Quick Links
- Community
- Getting Started
- FAQ
- Ranking Overview
- Rules of Participation
- Contact
- Email us
- Tell us what you think
- Information Libraries
- Integrated Systems
- Networking
- Servers
- Storage
- Other HPE Sites
- Support Center
- Enterprise.nxt
- Marketplace
- Aruba Airheads Community
-
Categories
-
Forums
-
Blogs
-
InformationEnglish
ACL to completely block IPv6 on 5700 FF
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
03-07-2016 01:15 AM
03-07-2016 01:15 AM
ACL to completely block IPv6 on 5700 FF
ACL to completely block IPv6 on 5700 FF
Hello everybody,
i have a question about ACL's. We have a customer who's using the HP 577 FF as LAN-Core. There are specific printers tha have varius problems with IPv6 Traffic. Sometimes, the whole Network is going down.
I want to block all IPv6 Traffic on the lan core. I've tried to create an ACL to block IPv6 but it didn't work. Can anybody tell me how to create the ACL rule correctly?
Thanks in advance!
Greetings Sebastian
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
03-07-2016 01:52 AM
03-07-2016 01:52 AM
Re: ACL to completely block IPv6 on 5700 FF
Re: ACL to completely block IPv6 on 5700 FF
What did you try?
I'd start using port based (not VLAN based) rules blocking "ipv6 any-any" in both in and out-going direction.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
03-07-2016 11:42 PM
03-07-2016 11:42 PM
Re: ACL to completely block IPv6 on 5700 FF
Re: ACL to completely block IPv6 on 5700 FF
Hey,
thanks for your reply.
I've tried the following command (as advanced IPv6 rule): rule deny ipv6 source any destination any
My current config:
[HP]dis acl ipv6 all
Advanced IPv6 ACL 3001, named -none-, 2 rules,
ACL's step is 5
rule 0 deny ipv6 logging
rule 1 deny icmpv6
I've also tried to set a second rule to deny icmpv6. But it seems, that none of the rules works properly. There's still IPv6 Traffic going through the device.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
03-08-2016 12:38 AM
03-08-2016 12:38 AM
Re: ACL to completely block IPv6 on 5700 FF
Re: ACL to completely block IPv6 on 5700 FF
Drop the "logging" on the ACL .
On lower end switches, logging only works om management plane ACL.
On switch fabric there's probably no logging possibility, so rule doesn't get applied
Hewlett Packard Enterprise International
- Communities
- HPE Blogs and Forum
© Copyright 2018 Hewlett Packard Enterprise Development LP