•
You must be familiar with IP addressing and protocols to configure IP ACLs.
•
You must be familiar with the interface types that you want to configure with ACLs.
Guidelines and Limitations for ACLs
IP ACLs have the following configuration guidelines and limitations:
•
As an enhancement to HTTP method match, the tcp-option-length option has been added to the ACE
syntax to specify the length of the TCP options header in the packets. You can configure up to 4
tcp-option-lengths in the ACEs, which includes the TCP option length of 0. If you do not configure the
tcp-option-length option, the length is considered as 0. It means that only the packets without the TCP
options header can match this ACE. This feature gives more flexibility in such a way that the HTTP
method can be matched even on the packets that have the variable length TCP options header.
•
We recommend that you perform ACL configuration using the Session Manager. This feature allows
you to verify ACL configuration and confirm that the resources required by the configuration are available
prior to committing them to the running configuration. This is especially useful for ACLs that include
more than about 1000 rules.
•
You can configure any number of ACLs as long as TCAM space is available.
•
Packets that fail the Layer 3 maximum transmission unit check and therefore require fragmenting.
•
IPv4 packets that have IP options (additional IP packet header fields following the destination address
field).
•
When you apply an ACL that uses time ranges, the device updates the ACL entries whenever a time
range referenced in an ACL entry starts or ends. Updates that are initiated by time ranges occur on a
best-effort priority. If the device is especially busy when a time range causes an update, the device may
delay the update by up to a few seconds. Make sure that the time range is valid and in an active state.
•
To use the
match-local-traffic
option for all inbound and outbound traffic, you must first enable the
ACL in the software.
Default ACL Settings
The following table lists the default settings for IP ACLs parameters.
Table 12: Default IP ACLs Parameters
Default
Parameters
No IP ACLs exist by default.
IP ACLs
Implicit rules apply to all ACLs .
ACL rules
The following table lists the default settings for MAC ACLs parameters.
Cisco Nexus 3600 NX-OS Security Configuration Guide, Release 7.x
80
Configuring IP ACLs
Guidelines and Limitations for ACLs
Содержание Nexus 3600 NX-OS
Страница 10: ...Cisco Nexus 3600 NX OS Security Configuration Guide Release 7 x x Contents ...
Страница 20: ...Cisco Nexus 3600 NX OS Security Configuration Guide Release 7 x 6 Overview IP ACLs ...
Страница 42: ...Cisco Nexus 3600 NX OS Security Configuration Guide Release 7 x 28 Configuring AAA Default AAA Settings ...