> ... and that did exactly nothing, as in "packets continue to flow" and
> "show access-list hardware counter" shows exactly no "Drop" hits either.

Iirc, at least on some platforms, mac access-list only match non-IP traffic. So 
when we are talking IP (or IPv6) traffic, you probably wanna try an actual IP 
access-list (an ipv6 access-list in this case).

You may need to apply such ACLs to the vlan (via vlan-maps), not directly to 
the port.

But this is very platform specific, so YMMV.


lukas

                                          
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to