Configure an IPv6 prefix list

Use IPv6 prefix lists in Firewall Threat Defense devices to specify which IPv6 routes are allowed or blocked during redistribution. This enhances routing policy control for protocols such as OSPF and BGP.

Procedure


Step 1

Select Objects > Prefix Lists > IPv6 Prefix List from the table of contents.

Step 2

Click Add Prefix List.

  1. Enter a name for the prefix list object in the Name field

  2. Click Add.

Step 3

Select the appropriate action, Allow or Block, from the Action drop-down list to indicate the redistribution access.

Step 4

Enter a unique number that indicates the position a new prefix list entry will have in the list of prefix list entries already configured for this object, in the Sequence No. field. If left blank, the sequence number will default to five more than the largest sequence number currently in use.

Step 5

Specify the IPv6 address in the IP address/mask length format in the IP address field. The mask length must be a valid value between 1 and 128.

Step 6

Enter the minimum prefix length in the Minimum Prefix Length field and the maximum prefix length in the Maximum Prefix Length field.

The minimum prefix length value must be greater than the mask length and less than or equal to the Maximum Prefix Length, if specified.

If the Minimum Prefix Length is present, the maximum prefix length value must be greater than or equal to it. If the Minimum Prefix Length is not specified, the maximum value must be greater than the mask length.

Step 7

Click Add.

Step 8

If you want to allow overrides for this object, check the Allow Overrides check box; see Allow object overrides.

Step 9

Click Save.