ACL Filter Policy Overview
Page 414
7750 SR OS Router Configuration Guide
Figure 16: IOM/CPM Filter Policy Using an Address Prefix Match List
Note:
The hardware resource usage does not change whether filter match lists are used or whether
operator creates multiple entries (each per one element of the list): however, a careful
consideration must be given to how the lists are used to ensure only desired match permutations
are created in a filter policy entry (especially when other matching criteria that are also lists or
ranges are specified in the same entry). The system verifies that a new list element, for example, an
IP address prefix, cannot be added to a given list or a list cannot be used by a new filter policy
unless resources exist in hardware to implement the required filter policy (ies) that reference that
list. If that is not the case, addition of a new element to the list or use of the list by another policy
will fail.
Some use cases like those driven by dynamic policy changes, may result in acceptance of filter
policy configuration changes that cannot be programmed in hardware because of the resource
exhaustion. If that is the case, when attempting to program a filter entry that uses a match list(s),
the operation will fail, the entry will be not programmed, and a notification of that failure will be
provided to an operator.
Please refer to SROS Release Notes for what objects can be grouped into a filter match list for
IOM and CPM filter policies.
Auto-generation of Filter-policy Address Prefix Match Lists
It is often desired to automatically update a filter policy when the configuration on a router
changes. To allow such a touch-less filter policy management, SROS allows auto-generation of
address prefixes for IPv4 or IPv6 address prefix match lists based on operator-configured criteria.
When the configuration on a router changes, the match lists address prefixes are automatically
updated and, in-turn, all filter policies (CPM or IOM) that use these match lists are automatically
updated.
Entry K
match: IPv4 Prefix List A
CPM Filter
IOM Filters
OSSG730
Entry M
match: IPv4 Prefix List A
IPv4 Prefix 1
IPv4 Prefix 2
IPv4 Prefix N
IPv4 Prefix List A
Содержание 7750 SR-OS
Страница 10: ...Page 10 7750 SR OS Router Configuration Guide List of Tables...
Страница 12: ...Page 12 7750 SR OS Router Configuration Guide List of Figures...
Страница 18: ...Getting Started Page 18 7750 SR OS Router Configuration Guide...
Страница 108: ...IP Router Command Reference Page 108 7750 SR OS Router Configuration Guide...
Страница 200: ...Router Advertisement Commands Page 200 7750 SR OS Router Configuration Guide...
Страница 269: ...IP Router Configuration 7750 SR OS Router Configuration Guide Page 269 LDP 1 1 SDP 1 1 A ALA A config service...
Страница 299: ...IP Router Configuration 7750 SR OS Router Configuration Guide Page 299...
Страница 300: ...Debug Commands Page 300 7750 SR OS Router Configuration Guide...
Страница 348: ...Page 348 7750 SR OS Router Configuration Guide...
Страница 388: ...Page 388 7750 SR OS Router Configuration Guide...
Страница 442: ...Configuration Notes Page 442 7750 SR OS Router Configuration Guide...
Страница 470: ...Filter Management Tasks Page 470 7750 SR OS Router Configuration Guide...
Страница 586: ...Configuration Notes Page 586 7750 SR OS Router Configuration Guide...
Страница 588: ...OpenFlow Command Reference Page 588 7750 SR OS Router Configuration Guide...
Страница 598: ...Show Commands Page 598 7750 SR OS Router Configuration Guide...
Страница 608: ...Page 608 7750 SR OS Router Configuration Guide...
Страница 646: ...Page 646 7750 SR OS Router Configuration Guide...
Страница 660: ...Page 660 7750 SR OS Router Configuration Guide...
Страница 666: ...Common CLI Command Descriptions Page 666 7750 SR OS Router Configuration Guide...