
BigIron RX Series Configuration Guide
525
53-1002253-01
ACL IDs and entries
21
Standard or extended ACLs can be numbered or named. Standard ACLs are numbered from 1 – 99,
extended ACLs are numbered 100 – 199. Super ACLs may be assigned numbered IDs only, from
500 - 599. IDs for standard or extended ACLs can also be a character string (named). In this
document, an ACL with a string ID is called a named ACL.
ACL IDs and entries
ACLs consist of ACL IDs and ACL entries:
•
ACL ID – An ACL ID is a number from 1 – 99 (standard), 100 – 199 (extended) or 500 – 599
(super) or a character string (super ACLs are numbered only). The ACL ID identifies a collection
of individual ACL entries. When you apply ACL entries to an interface, you do so by applying the
ACL ID that contains the ACL entries to the interface, instead of applying the individual entries
to the interface. This makes it easier to apply large groups of access filters (ACL entries) to
interfaces.
NOTE
This process differs from the process of assigning IP access policies. When you use IP access
policies, you apply the individual policies directly to the interfaces.
•
ACL entry – An ACL entry contains the filter commands associated with an ACL ID. These are
also called “statements.” The maximum number of ACL entries you can configure is a
system-wide parameter and depends on the BigIron RX you are configuring. You can configure
up to the maximum number of entries in any combination in different ACLs. The total number
of entries in all ACLs cannot exceed the system maximum.
You configure ACLs on a global basis, then apply them to the incoming traffic on specific ports. You
can apply only one ACL to a port’s inbound traffic. The software applies the entries within an ACL in
the order they appear in the ACL’s configuration. As soon as a match is found, the software takes
the action specified in the ACL entry (for example, permit or deny the packet) and stops further
comparison for that packet.
Enabling support for additional ACL statements
You can enable support for additional ACL statements if the BigIron RX has enough space for a
startup-config file that contains the ACLs. Enter the following command at the Global CONFIG level
of the CLI.
BigIron RX(config)# system-max ip-filter-sys 5000
Syntax: [no] system-max ip-filter-sys
<num>
Enter up to 8000 for
<num>
. The default is 4000 statements.
You can load ACLs dynamically by saving them in an external configuration file on a flash card or a
TFTP server, then loading them using one of the following commands:
•
copy slot1 | slot2 running
<from-name>
•
ncopy slot1 | slot2
<from-name>
running
•
copy tftp running-config
<ip-addr>
<filename>
•
ncopy tftp
<ip-addr> <from-name>
running-config
In this case, the ACLs are added to the existing configuration.
Содержание BigIron RX Series
Страница 100: ...24 BigIron RX Series Configuration Guide 53 1002253 01 Logging on through the Web Management Interface 2 ...
Страница 192: ...116 BigIron RX Series Configuration Guide 53 1002253 01 Configuring authentication method lists 4 ...
Страница 228: ...152 BigIron RX Series Configuration Guide 53 1002253 01 Enabling WAN PHY mode support 6 ...
Страница 312: ...236 BigIron RX Series Configuration Guide 53 1002253 01 Displaying IP information 7 ...
Страница 356: ...280 BigIron RX Series Configuration Guide 53 1002253 01 Resetting LLDP statistics 9 ...
Страница 402: ...326 BigIron RX Series Configuration Guide 53 1002253 01 Transparent firewall mode 11 ...
Страница 432: ...356 BigIron RX Series Configuration Guide 53 1002253 01 SuperSpan 12 ...
Страница 500: ...424 BigIron RX Series Configuration Guide 53 1002253 01 MRP CLI example 14 ...
Страница 580: ...504 BigIron RX Series Configuration Guide 53 1002253 01 Configuring multicast traffic engineering 18 ...
Страница 591: ...BigIron RX Series Configuration Guide 515 53 1002253 01 Displaying traffic reduction 19 ...
Страница 592: ...516 BigIron RX Series Configuration Guide 53 1002253 01 Displaying traffic reduction 19 ...
Страница 598: ...522 BigIron RX Series Configuration Guide 53 1002253 01 Viewing Layer 2 ACLs 20 ...
Страница 656: ...580 BigIron RX Series Configuration Guide 53 1002253 01 Trunk formation 22 ...
Страница 754: ...678 BigIron RX Series Configuration Guide 53 1002253 01 Displaying RIP filters 24 ...
Страница 814: ...738 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPF information 25 ...
Страница 932: ...856 BigIron RX Series Configuration Guide 53 1002253 01 Generalized TTL security mechanism support 26 ...
Страница 980: ...904 BigIron RX Series Configuration Guide 53 1002253 01 Clearing IS IS information 28 ...
Страница 1000: ...924 BigIron RX Series Configuration Guide 53 1002253 01 Using secure copy 30 ...
Страница 1088: ...1012 BigIron RX Series Configuration Guide 53 1002253 01 IP source guard 35 ...
Страница 1108: ...1032 BigIron RX Series Configuration Guide 53 1002253 01 Reading CDP packets 37 ...
Страница 1126: ...1050 BigIron RX Series Configuration Guide 53 1002253 01 Clearing sFlow statistics 39 ...
Страница 1140: ...1064 BigIron RX Series Configuration Guide 53 1002253 01 802 1s Multiple Spanning Tree Protocol 40 ...
Страница 1324: ...1248 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPFv3 information 48 ...
Страница 1363: ...BigIron RX Series Configuration Guide 1287 53 1002253 01 Continuous System Monitor 51 ...
Страница 1364: ...1288 BigIron RX Series Configuration Guide 53 1002253 01 Continuous System Monitor 51 ...
Страница 1404: ...1328 BigIron RX Series Configuration Guide 53 1002253 01 Commands That Require a Reload D ...
Страница 1458: ...1382 BigIron RX Series Configuration Guide 53 1002253 01 VSRP E ...