<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking IPv6 on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5152896#M1114715</link>
    <description>&lt;P&gt;I believe that in the routed firewall mode ASA drops all IPv6 if IPv6 addresses are not configured on ASA interfaces, simply because its IPv6 routing table is empty in this case. Transparent firewall mode also requires IPv6 address to be configured.&lt;/P&gt;&lt;P&gt;NB. In ASA ACLs "any" means "any4" OR "any6", so if IPv6 addresses are configured on ASA interfaces, it may let IPv6 through "any" depending on your configuration.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jul 2024 14:29:31 GMT</pubDate>
    <dc:creator>tvotna</dc:creator>
    <dc:date>2024-07-29T14:29:31Z</dc:date>
    <item>
      <title>Blocking IPv6 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5151780#M1114664</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;is IPv6 blocked on Cisco ASA by default? we are running version 9.12 currently and have received a request to block an IPv6 address&amp;nbsp; and I am pretty sure we haven't used IPv6 in our environment before. So was wondering if we need to take any action on the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vijay&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 10:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5151780#M1114664</guid>
      <dc:creator>vijay4211</dc:creator>
      <dc:date>2024-07-26T10:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IPv6 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5151783#M1114666</link>
      <description>&lt;P&gt;Do you have any attack to your VPN service and you want to deny this IP to access ASA?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 10:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5151783#M1114666</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-26T10:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IPv6 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5151812#M1114667</link>
      <description>&lt;P&gt;Hi MHM,&lt;/P&gt;&lt;P&gt;No, not for this. Actually this is an internet facing firewall and we block malicious IPs coming on our outside interface as provided by our SOC advisories. But this is the first time we have received a request for an IPv6 address.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 11:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5151812#M1114667</guid>
      <dc:creator>vijay4211</dc:creator>
      <dc:date>2024-07-26T11:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IPv6 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5152088#M1114673</link>
      <description>&lt;P&gt;Anyone has any idea on whether we should be blocking this Ipv6 address through, say an ACL, or will it get blocked by default?&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jul 2024 06:49:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5152088#M1114673</guid>
      <dc:creator>vijay4211</dc:creator>
      <dc:date>2024-07-27T06:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IPv6 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5152896#M1114715</link>
      <description>&lt;P&gt;I believe that in the routed firewall mode ASA drops all IPv6 if IPv6 addresses are not configured on ASA interfaces, simply because its IPv6 routing table is empty in this case. Transparent firewall mode also requires IPv6 address to be configured.&lt;/P&gt;&lt;P&gt;NB. In ASA ACLs "any" means "any4" OR "any6", so if IPv6 addresses are configured on ASA interfaces, it may let IPv6 through "any" depending on your configuration.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 14:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5152896#M1114715</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-07-29T14:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IPv6 on ASA</title>
      <link>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5152902#M1114717</link>
      <description>&lt;P&gt;defualt behavior of asa is prevent any traffic from low to high secuirty even if you not config ACL and this inlcude both ipv4 and ipv6&lt;/P&gt;
&lt;P&gt;But to be sure I run lab yesterday to add ipv6 access-list any any log&amp;nbsp; to OUT of asa but the command is unknown'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry I have limit time these day I will try soon and update you when I sucess&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 15:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-ipv6-on-asa/m-p/5152902#M1114717</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-29T15:00:11Z</dc:date>
    </item>
  </channel>
</rss>

