
524
BigIron RX Series Configuration Guide
53-1002253-01
Disabling or re-enabling Access Control Lists (ACLs)
21
RX-BI-16XG (16 x 10GE ) Module EGRESS ACL Configuration Guidelines
•
The RX-BI-16XG 16 x 10GE module only supports standard, extended, named, and
numbered ACLs for outbound access-group applications ACLs.
•
Egress filtering on subset ports of a VE is not supported, matching must apply to all VE
ports .
•
Matching the SPI field value is not supported for egress acl.
•
Matching field of fragment or fragmentation-offset is not supported.
•
A matching egress acl only compares to 3 bits of TOS field (delay, throughput, reliability)
•
ACLs that specify spi, .tos min monrtary cost, fragment or fragmentation-offset will cause
a configuration conflict and an error message "ACL configuration conflict specified filter
not supported" is entered in syslog.
•
802.1p-priority is not supported as a matching egress acl condition.
•
dscp-marking is not available as a condition matching egress acl action.
•
deny-logging is not supported for egress ACLs.
Disabling or re-enabling Access Control Lists (ACLs)
The ACL feature is always enabled on BigIron RX; it cannot be disabled.
Default ACL action
The default action when no ACLs are configured on a BigIron RX is to permit all traffic. However,
once you configure an ACL and apply it to a port, the default action for that port is to deny all traffic
that is not explicitly permitted on the port.
•
To control access more tightly, configure ACLs consisting of permit entries for the access you
want to permit. The ACLs implicitly deny all other access.
•
To secure access in environments with many users, you can configure ACLs that consist of
explicit deny entries, then add an entry to permit all access to the end of each ACL. The
software permits packets that are not denied by the deny entries.
NOTE
Do not apply an empty ACL (an ACL ID without any corresponding entries) to an interface. If you
accidentally do this, the software applies the default ACL action, deny all, to the interface and thus
denies all traffic.
Types of IP ACLs
IP ACLs can be configured as standard, extended, or super. A standard ACL permits or denies
packets based on a source IP address. An extended ACL permits or denies packets based on
source and destination IP addresses and also based on IP protocol information. Super ACLs can
match on any field in a packet header from Layer 2 to Layer 4. Super ACLs support all options
currently supported in ACL and MAC ACL, including QoS marking.
Содержание BigIron RX Series
Страница 100: ...24 BigIron RX Series Configuration Guide 53 1002253 01 Logging on through the Web Management Interface 2 ...
Страница 192: ...116 BigIron RX Series Configuration Guide 53 1002253 01 Configuring authentication method lists 4 ...
Страница 228: ...152 BigIron RX Series Configuration Guide 53 1002253 01 Enabling WAN PHY mode support 6 ...
Страница 312: ...236 BigIron RX Series Configuration Guide 53 1002253 01 Displaying IP information 7 ...
Страница 356: ...280 BigIron RX Series Configuration Guide 53 1002253 01 Resetting LLDP statistics 9 ...
Страница 402: ...326 BigIron RX Series Configuration Guide 53 1002253 01 Transparent firewall mode 11 ...
Страница 432: ...356 BigIron RX Series Configuration Guide 53 1002253 01 SuperSpan 12 ...
Страница 500: ...424 BigIron RX Series Configuration Guide 53 1002253 01 MRP CLI example 14 ...
Страница 580: ...504 BigIron RX Series Configuration Guide 53 1002253 01 Configuring multicast traffic engineering 18 ...
Страница 591: ...BigIron RX Series Configuration Guide 515 53 1002253 01 Displaying traffic reduction 19 ...
Страница 592: ...516 BigIron RX Series Configuration Guide 53 1002253 01 Displaying traffic reduction 19 ...
Страница 598: ...522 BigIron RX Series Configuration Guide 53 1002253 01 Viewing Layer 2 ACLs 20 ...
Страница 656: ...580 BigIron RX Series Configuration Guide 53 1002253 01 Trunk formation 22 ...
Страница 754: ...678 BigIron RX Series Configuration Guide 53 1002253 01 Displaying RIP filters 24 ...
Страница 814: ...738 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPF information 25 ...
Страница 932: ...856 BigIron RX Series Configuration Guide 53 1002253 01 Generalized TTL security mechanism support 26 ...
Страница 980: ...904 BigIron RX Series Configuration Guide 53 1002253 01 Clearing IS IS information 28 ...
Страница 1000: ...924 BigIron RX Series Configuration Guide 53 1002253 01 Using secure copy 30 ...
Страница 1088: ...1012 BigIron RX Series Configuration Guide 53 1002253 01 IP source guard 35 ...
Страница 1108: ...1032 BigIron RX Series Configuration Guide 53 1002253 01 Reading CDP packets 37 ...
Страница 1126: ...1050 BigIron RX Series Configuration Guide 53 1002253 01 Clearing sFlow statistics 39 ...
Страница 1140: ...1064 BigIron RX Series Configuration Guide 53 1002253 01 802 1s Multiple Spanning Tree Protocol 40 ...
Страница 1324: ...1248 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPFv3 information 48 ...
Страница 1363: ...BigIron RX Series Configuration Guide 1287 53 1002253 01 Continuous System Monitor 51 ...
Страница 1364: ...1288 BigIron RX Series Configuration Guide 53 1002253 01 Continuous System Monitor 51 ...
Страница 1404: ...1328 BigIron RX Series Configuration Guide 53 1002253 01 Commands That Require a Reload D ...
Страница 1458: ...1382 BigIron RX Series Configuration Guide 53 1002253 01 VSRP E ...