512
BigIron RX Series Configuration Guide
53-1001810-01
How the device processes ACLs
21
How the device processes ACLs
The device processes traffic that ACLs filter in hardware. The device creates an entry for each ACL
in the Content Addressable Memory (CAM) at startup or when the ACL is created. The device uses
these CAM entries to permit or deny packets in the hardware, without sending the packets to the
CPU for processing.
General configuration guidelines
•
ACLs are supported on physical interfaces, trunk groups, and virtual routing interfaces.
•
ACLs are supported only for inbound traffic. An error message is displayed if you apply an ACL
to an outbound interface.
•
You can create up to 416 CAM entries, but you can have up to 8,000 statements (rules) in all
the ACL configurations on the device. Default is 4096 statements.
•
A port supports only one ACL; however, the ACL can contain multiple statements. For example,
both ACLs 101 and 102 cannot be supported on port 1, but ACL 101 can contain multiple
entries.
•
If you change the content of an ACL (add, change, or delete entries), you must remove and then
reapply the ACL to all the ports that use it. Otherwise, the older version of the ACL remains in
the CAM and continues to be used. You can easily re-apply ACLs using the ip rebind-acl
<num>
|
<name>
| all command. Refer to
“Applying ACLs to interfaces”
on page 551.
•
You cannot enable any of the following features on the interface if an ACL is already applied to
that interface:
•
Protection against ICMP or TCP Denial-of-Service (DoS) Attacks
•
ACL-based rate limiting
•
ACL Logging
•
Policy-based routing (PBR)
RX-BI-16XG (16 x 10GE ) Module EGRESS ACLconfiguration guidelines
•
The RX-BI-16XG 16 x 10GE module only supports standard, extended, named, and
numbered ACLs for outbound access-group applicationsACLs.
•
Egress filtering on subset ports of a VE is not supported, matching must apply to all VE
ports .
•
Matching the SPI field value is not supported for egress acl.
•
Matching field of fragment or fragmentation-offset is not supported.
•
A matching egress acl only compares to 3 bits of TOS field (delay, throughput, reliability)
•
ACLs that specify spi, .tos min monrtary cost, fragment or fragmentation-offset will cause
a configuration conflict and an error message "ACL configuration conflict specified filter
not supported" is entered in syslog.
•
802.1p-priority is not supported as a matching egress acl condition.
•
dscp-marking is not available as a condition matching egress acl action.
•
deny-logging is not supported for egress ACLs.
Содержание Brocade DCX
Страница 40: ...xl BigIron RX Series Configuration Guide 53 1001810 01 ...
Страница 72: ...lxxii BigIron RX Series Configuration Guide 53 1001810 01 ...
Страница 88: ...16 BigIron RX Series Configuration Guide 53 1001810 01 Searching and filtering output 1 ...
Страница 300: ...228 BigIron RX Series Configuration Guide 53 1001810 01 Displaying IP information 7 ...
Страница 318: ...246 BigIron RX Series Configuration Guide 53 1001810 01 Deploying a LAG 8 ...
Страница 418: ...346 BigIron RX Series Configuration Guide 53 1001810 01 SuperSpan 12 ...
Страница 482: ...410 BigIron RX Series Configuration Guide 53 1001810 01 MRP CLI example 14 ...
Страница 506: ...434 BigIron RX Series Configuration Guide 53 1001810 01 Displaying VSRP information 15 ...
Страница 566: ...494 BigIron RX Series Configuration Guide 53 1001810 01 QoS for the oversubscribed 16 x 10GE modules 18 ...
Страница 582: ...510 BigIron RX Series Configuration Guide 53 1001810 01 Viewing Layer 2 ACLs 20 ...
Страница 634: ...562 BigIron RX Series Configuration Guide 53 1001810 01 Troubleshooting ACLs 21 ...
Страница 642: ...570 BigIron RX Series Configuration Guide 53 1001810 01 Trunk formation 22 ...
Страница 746: ...674 BigIron RX Series Configuration Guide 53 1001810 01 Displaying RIP filters 24 ...
Страница 808: ...736 BigIron RX Series Configuration Guide 53 1001810 01 Displaying OSPF information 25 ...
Страница 926: ...854 BigIron RX Series Configuration Guide 53 1001810 01 Generalized TTL security mechanism support 26 ...
Страница 938: ...866 BigIron RX Series Configuration Guide 53 1001810 01 Displaying MBGP information 27 ...
Страница 950: ...878 BigIron RX Series Configuration Guide 53 1001810 01 Using secure copy 28 ...
Страница 988: ...916 BigIron RX Series Configuration Guide 53 1001810 01 Clearing IS IS information 29 ...
Страница 998: ...926 BigIron RX Series Configuration Guide 53 1001810 01 Configuring BFD for the specified protocol 30 ...
Страница 1014: ...942 BigIron RX Series Configuration Guide 53 1001810 01 Displaying multi device port authentication information 31 ...
Страница 1054: ...982 BigIron RX Series Configuration Guide 53 1001810 01 Sample 802 1x configurations 33 ...
Страница 1072: ...1000 BigIron RX Series Configuration Guide 53 1001810 01 IP source guard 35 Syntax show ip source guard ethernet port num ...
Страница 1108: ...1036 BigIron RX Series Configuration Guide 53 1001810 01 sFlow 39 ...
Страница 1190: ...1118 BigIron RX Series Configuration Guide 53 1001810 01 Displaying RIPng information 44 ...
Страница 1270: ...1198 BigIron RX Series Configuration Guide 53 1001810 01 Displaying ACLs 47 ...
Страница 1310: ...1238 BigIron RX Series Configuration Guide 53 1001810 01 Displaying OSPFv3 information 48 ...
Страница 1382: ...1310 BigIron RX Series Configuration Guide 53 1001810 01 Commands That Require a Reload D ...
Страница 1435: ...BigIron RX Series Configuration Guide 1363 53 1001810 01 VSRP E ...
Страница 1436: ...1364 BigIron RX Series Configuration Guide 53 1001810 01 VSRP E ...