Creating an IPv6 Firewall Policy
The following procedure describes how to create an IPv6firewallFirewall is a network security system used for preventing unauthorized access to or from a private network.policy.
1.In the node hierarchy, navigate to the tab.
2.Click to create a new policy.
3.Enter for the .
4.To configure afirewallFirewall is a network security system used for preventing unauthorized access to or from a private network.policy, select for .
5.Click .
6.Select the policy.
7.Click in the rules table.
8.Select option in the field and click .
9.Select from the drop-down list.
10.Select from the drop-down list and enter the following values:
a.For , enter .
b。For , enter as the prefix-length.
c.For 中,选择 from the drop-down list.
d.For 中,选择 from the drop-down list.
e.Click .
11.Click 添加规则,允许HTTPSHypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection.traffic.
12.Select option in the field and click .
a.Under column, select
b。Select from the drop-down list.
c.For , enter .
d.For , enter as the prefix-length.
e.Under 中,选择 from the drop-down list.
f.Select from the scrolling list.
g.Click .
Rules can be reordered using the up and down arrow buttons provided for each rule. |
13.Click .
14.In the window, select the check box and click .
The followingCLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.commands create an IPv6firewallFirewall is a network security system used for preventing unauthorized access to or from a private network.policy.
(host) [md] (config)#ip access-list session ipv6-web-only
(host) [md] (config-submode)#ipv6 network 2002:d81f:f9f0:1000::/64 any svc-http permit
(host) [md] (config-submode)#ipv6 network 2002:d81f:f9f0:1000::/64 any svc-https permit