IPv6 ISP with Cisco 1841 router
IPv6 ISP with Cisco 1841 router
(OP)
I use a Cisco 1841 router as my firewall. Mediacom my ISP just enabled IPv6 support. I have it working now, but trying to track down a good ACL for inbound traffic. I want to block pings but at the same time must allow for DHCP and PD to work correctly. Currently this is my working access list:
ipv6 access-list IPv6_In
permit udp FE80::/64 any eq 546
permit icmp any any unreachable
permit icmp any any packet-too-big
permit icmp any any hop-limit
permit icmp any any next-header
permit icmp any any parameter-option
permit icmp any any reassembly-timeout
permit icmp any any header
permit icmp any any router-advertisement
permit icmp any any nd-ns
permit icmp any any nd-na
deny ipv6 any any log
Should all of my entries be sourced by FE80::/64 and not "any"?
ipv6 access-list IPv6_In
permit udp FE80::/64 any eq 546
permit icmp any any unreachable
permit icmp any any packet-too-big
permit icmp any any hop-limit
permit icmp any any next-header
permit icmp any any parameter-option
permit icmp any any reassembly-timeout
permit icmp any any header
permit icmp any any router-advertisement
permit icmp any any nd-ns
permit icmp any any nd-na
deny ipv6 any any log
Should all of my entries be sourced by FE80::/64 and not "any"?
CCNA, A+, HP Certified Professional
RE: IPv6 ISP with Cisco 1841 router
How does someone get fragmentation working, yet lock down the router at the same time? But not effect performance?
===========================
no ipv6 source-route
ipv6 unicast-routing
ipv6 cef
ipv6 inspect name IPv6 icmp timeout 60
ipv6 inspect name IPv6 ftp timeout 60
ipv6 inspect name IPv6 tcp timeout 60
ipv6 inspect name IPv6 udp timeout 60
interface FastEthernet0/0
ipv6 address dhcp
ipv6 address autoconfig default
ipv6 enable
no ipv6 redirects
no ipv6 unreachables
ipv6 verify unicast reverse-path
ipv6 dhcp client pd mediacom
ipv6 inspect IPv6 out
ipv6 traffic-filter IPv6_In in
interface FastEthernet0/1
ipv6 address mediacom ::1/64
ipv6 enable
ipv6 access-list IPv6_In
permit udp FE80::/64 any eq 546
permit icmp FE80::/64 any router-advertisement
permit icmp FE80::/64 any nd-ns
permit icmp FE80::/64 any nd-na
permit icmp FE80::/64 any mld-report
deny ipv6 any any log
CCNA, A+, HP Certified Professional