62-11
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 62 Configuring Network Security with ACLs
Layer 4 Operators in ACLs
Restrictions for Layer 4 Operations
Note
Cisco IOS XE Release 3.7.0E and Cisco IOS Release 15.2(3)E do not support the configuration of named
ACLs for noncontiguous ports on an ACE.
You can specify these operator types, each of which uses one Layer 4 operation in the hardware:
•
gt (greater than)
•
lt (less than)
•
neq (not equal)
•
range (inclusive range)
The limits on the number of Layer 4 operations differ for each type of ACL, and can also vary based on
other factors: whether an ACL is applied to incoming or outgoing traffic, whether the ACL is a security
ACL or is used as a match condition for a QoS policy, and whether IPv6 ACLs are being programmed
using the compressed flow label format.
Note
The IPv6 compressed flow label format uses the Layer 2 Address Table to compress a portion of the IPv6
source address of each ACE in the ACL. The extra space freed in the flow label can then be used to
support more Layer 4 operations. For this compression to be used, the IPv6 ACL cannot contain any
ACEs that mask in only a portion of the bottom 48 bits of the source IPv6 address.
Generally, you will receive at most the following number of Layer 4 operations on the same ACL:
Direction Protocol Type Operations
------------------------------------------------
Input IPv4 Security 16
Input IPv6 Compressed Security 16
Input IPv6 Uncompressed Security 7
Input IPv4 QoS 5
Input IPv6 Compressed QoS 12
Input IPv6 Uncompressed QoS 8
Output IPv4 Security 17
Output IPv6 Compressed Security 17
Output IPv6 Uncompressed Security 8
Output IPv4 QoS 5
Output IPv6 Compressed QoS 12
Output IPv6 Uncompressed QoS 8
Note
Where up to 16 operations are supported, the seventeenth will trigger an expansion.
If you exceed the number of available Layer 4 operations, each new operation might cause the affected
ACE to be translated into multiple ACEs in the hardware. If this translation fails, packets are sent to the
CPU for software processing.
When you globally enable the
ipv6 multicast-routing
and
ipv6 routing
global configuration
commands, a reduced number of Layer 4 operations are available for use in IPv6 ACL or QoS.
Additionally, the "eq" operator consumes a Layer 4 Operation if it is used to match a source port.
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...