ArubaOS 8.6.0.0Help Center
You are here: Home > IPv6 > ArubaOS Features that Support IPv6 > Creating an IPv6 Firewall Policy

Creating an IPv6 Firewall Policy

The following procedure describes how to create an IPv6firewallFirewall is a network security system used for preventing unauthorized access to or from a private network.policy.

1.In theManaged Networknode hierarchy, navigate to theConfiguration > Roles & Policies > Policiestab.

2.Click+to create a new policy.

3.Enteripv6-web-onlyfor thePolicy name.

4.To configure afirewallFirewall is a network security system used for preventing unauthorized access to or from a private network.policy, selectSessionforPolicy type.

5.ClickSubmit.

6.Select theipv6-web-onlypolicy.

7.Click+in thePolicy > ipv6-web-onlyrules table.

8.SelectAccess Controloption in theRule Typefield and clickOK.

9.SelectIPv6from theIP versiondrop-down list.

10.SelectNetworkfrom theSourcedrop-down list and enter the following values:

a.ForIPv6 address, enter2002:d81f:f9f0:1000::.

b。ForIPv6 Netmask, enter64as the prefix-length.

c.ForService/app中,选择Servicefrom the drop-down list.

d.ForServicealias中,选择svc-httpfrom the drop-down list.

e.ClickSubmit.

11.Click+Policy > ipv6-web-onlyRules table添加规则,允许HTTPSHypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection.traffic.

12.SelectAccess Controloption in theRule Typefield and clickOK.

a.UnderIP Versioncolumn, selectIPv6.

b。SelectNetworkfrom theSourcedrop-down list.

c.ForIP, enter2002:d81f:f9f0:1000::.

d.ForNetmask, enter64as the prefix-length.

e.UnderService/app中,选择Servicefrom the drop-down list.

f.Selectsvc-httpsfrom the scrolling list.

g.ClickSubmit.

Rules can be reordered using the up and down arrow buttons provided for each rule.

13.ClickPending Changes.

14.In thePending Changeswindow, select the check box and clickDeploy changes.

The followingCLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.commands create an IPv6firewallFirewall is a network security system used for preventing unauthorized access to or from a private network.policy.

(host) [md] (config)#ip access-list session ipv6-web-only

(host) [md] (config-submode)#ipv6 network 2002:d81f:f9f0:1000::/64 any svc-http permit

(host) [md] (config-submode)#ipv6 network 2002:d81f:f9f0:1000::/64 any svc-https permit

/*]]>*/
Baidu