Skip to main content

IPv6 Access Control List Definition

Access lists configured through localized data policy are called explicit ACLs. Explicit ACLs can be applied to any interface in any VPN on the device.

Diagram

Classes

definitions (sdwan.localized_policies)

NameTypeConstraintMandatoryDefault Value
ipv6_access_control_listsList[ipv6_access_control_lists]No

ipv6_access_control_lists (sdwan.localized_policies.definitions)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[A-Za-z0-9-_]{1,128}$Yes
descriptionStringYes
default_actionChoiceaccept, dropYes
sequencesList[sequences]No

sequences (sdwan.localized_policies.definitions.ipv6_access_control_lists)

NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 65534Yes
nameStringNo
base_actionChoiceaccept, dropYes
match_criteriasClass[match_criterias]No
actionsClass[actions]No

match_criterias (sdwan.localized_policies.definitions.ipv6_access_control_lists.sequences)

NameTypeConstraintMandatoryDefault Value
classStringRegex: ^[A-Za-z0-9-_]{1,128}$No
destination_data_prefix_listStringRegex: ^[A-Za-z0-9-_]{1,128}$No
destination_ip_prefixIPNo
destination_port_rangesList[destination_port_ranges]No
destination_portsListInteger[min: 0, max: 65535]No
next_headerIntegermin: 0, max: 255No
packet_lengthIntegermin: 0, max: 65535No
priorityChoicehigh, lowNo
source_data_prefix_listStringRegex: ^[A-Za-z0-9-_]{1,128}$No
source_ip_prefixIPNo
source_port_rangesList[source_port_ranges]No
source_portsListInteger[min: 0, max: 65535]No
tcpChoicesynNo
traffic_classIntegermin: 0, max: 63No

actions (sdwan.localized_policies.definitions.ipv6_access_control_lists.sequences)

NameTypeConstraintMandatoryDefault Value
classStringRegex: ^[A-Za-z0-9-_]{1,128}$No
counter_nameStringmin: 1, max: 20No
logBooleantrue, falseNo
mirror_listStringRegex: ^[A-Za-z0-9-_]{1,128}$No
next_hopIPNo
policerStringRegex: ^[A-Za-z0-9-_]{1,128}$No
traffic_classIntegermin: 0, max: 63No

destination_port_ranges (sdwan.localized_policies.definitions.ipv6_access_control_lists.sequences.match_criterias)

NameTypeConstraintMandatoryDefault Value
fromIntegermin: 0, max: 65535Yes
toIntegermin: 0, max: 65535Yes

source_port_ranges (sdwan.localized_policies.definitions.ipv6_access_control_lists.sequences.match_criterias)

NameTypeConstraintMandatoryDefault Value
fromIntegermin: 0, max: 65535Yes
toIntegermin: 0, max: 65535Yes

Examples

sdwan:
localized_policies:
definitions:
ipv6_access_control_lists:
- name: ACL-TLOCEXT-DSCP
description: "Set traffic class based on DSCP or port"
default_action: accept
sequences:
- id: 10
name: QoS-ACL
base_action: accept
match_criterias:
traffic_class: 46
source_port_ranges:
- from: 1000
to: 1050
actions:
class: CLASS-REALTIME
counter_name: 10-CLASS-REALTIME
- id: 20
name: AF13 traffic
base_action: accept
match_criterias:
source_ports:
- 100
- 240
traffic_class: 14
actions:
class: CLASS-BUSINESS
counter_name: 20-CLASS-BUSINESS