Chapter 33: Access Control Lists
STANDARD Revision 1.0
C4® CMTS Release 8.3 User Guide
© 2016 ARRIS Enterprises LLC. All Rights Reserved.
949
For example, the data plane filter ACL application classifies packets and either transmits them (permit action) or drops
them (deny action).
It is important to note that, depending on the nature of the ACL application, implementation is provided either within the
hardware-based data plane infrastructure, or within the software-based control plane.
Note that there are two applications that can be configured to reference an ACL for filtering purposes on the Router
Control Module (RCM) data plane. These are described in more detail in this chapter and include:
Data Plane Filter ACLs
SCM Access ACLs
The C4/c CMTS relies on the RCM to provide generic support for Data Plane Filter ACLs on all Ethernet and CAM interfaces.
In addition, it enables a user to enter a command to display the number of times each ACL entry was matched.
The C4/c CMTS supports IPv4 standard access lists, which have a range of 1-99. Determining the maximum number of ACL
entries that the Data Plane can hold is notably affected by those created using the range keyword. Entries created with a
range take up more physical space than those created without ranges. Extended access lists are supported for IPv4 and for
IPv6. These lists have a range of 100-199. The C4/c CMTS supports a total of 2048 access list entries and up to 1024 entries
per access list.
Note: IPv6 ACLs are limited to include entries with Source IP only. The CMTS does not support IPv6 ACL entries with any
other match criteria. The C4 CMTS does not support extended IPv6 ACLs.
IPv6 ACLs are assigned an access list name rather than a number by the operator. A number from 200-399 is automatically
generated internally.
Named Access Lists
Named Access Lists allow deleting and appending entries to an access-list. Users can add names, insert new entries mid-list
using indexes, and add multiple remarks per access-list entry. When new entries are inserted in a preexisting list, the
chassis renumbers the entries. Finally, an access list may start with a remark.
Index numbers may not be reused. They must be explicitly deleted first. If no index number is supplied, the command is
appended to the end of the list using a number equal to the last index value plus ten.
Limitations on assigning names to ACLs include:
Only one name can be assigned to an acl-num (ACL number)