IPv4, IPv6 and MAC ACLs

Forwarding Reference is not supported in ACL. If ACL is not created for RESTCONF, then you cannot bind an ACL on an interface.

You cannot delete an ACL, if it is bind on any interface. For this, delete the ACL binding and then delete ACL for RESTCONF.

If you want to update a filter of a particular sequence ID, first delete the filter and then add it back with modification.

Standard Named ACL is not possible.

Supported HTTP Operations for IPv4 ACL

PATCH method

To create IPv4 ACL and adding filter

URL: https://<host>/restconf/data/acl/acl-sets
{
    "acl-sets": {
        "acl-set": [
            {
                "name": "ext3",
                "type": "ACL_IPV4",
                "config": {
                    "name": "ext3",
                    "type": "ACL_IPV4"
                },
                "acl-entries": {
                    "acl-entry": [
                        {
                            "sequence-id": 10,
                            "config": {
                                "sequence-id": 10
                            },
                            "ipv4": {
                                "config": {
                                    "source-address": "10.0.0.0",
                                    "destination-address": "20.0.0.0/24",
                                    "dscp": 10,
                                    "protocol": 6,
                                    "internal-priority-marking": {
                                    "internal-priority-marking" : 7
                                    },
                                    "dscp-marking": {
                                    "dscp-marking" : 10
                                    }
                                }
                            },
                            "transport": {
                                "config": {
                                    "source-port": "0",
                                    "destination-port": "0"
                                }
                            },
                            "actions": {
                                "config": {
                                    "forwarding-action": "openconfig-acl:ACCEPT"
                                }
                            }
                        }
                    ]
                }
            }
        ]
    }
}

POST method

To create IPv4 ACL and adding filter

URL: https://<host>/restconf/data/acl/acl-sets
{
    "acl-set": [
        {
            "name": "ext_acl1",
            "type": "ACL_IPV4",
            "config": {
                "name": "ext_acl1",
                "type": "ACL_IPV4"
            },
            "acl-entries": {
                "acl-entry": [
                    {
                        "sequence-id": 10,
                        "config": {
                            "sequence-id": 10
                        },
                        "ipv4": {
                            "config": {
                                "source-address": "20.0.0.0/24",
                                "destination-address": "30.0.0.0/24",
                                "dscp": 10,
                                "protocol": 6,
                                "internal-priority-marking": {
                                    "internal-priority-marking" : 7
                                    },
                                    "dscp-marking": {
                                    "dscp-marking" : 10
                                    }
                            }
                        },
                        "transport": {
                            "config": {
                                "source-port": "0",
                                "destination-port": "0"
                            }
                        },
                        "actions": {
                            "config": {
                                "forwarding-action": "openconfig-acl:ACCEPT"
                            }
                        }
                    }
                ]
            }
        }
    ]
}

POST method (Binding on interface)

URL: https://<host>/restconf/data/acl
{
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/8",
                "config": {
                    "id": "ethernet 1/1/8"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "ext3",
                            "type": "ACL_IPV4",
                            "config": {
                                "set-name": "ext3",
                                "type": "ACL_IPV4"
                            }
                        }
                    ]
                }
            }
        ]
    }
}

PATCH method (Binding on ingress and egress interface)

URL: https://<host>/restconf/data/acl
{
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/1",
                "config": {
                    "id": "ethernet 1/1/1"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "ext_acl1",
                            "type": "ACL_IPV4",
                            "config": {
                                "set-name": "ext_acl1",
                                "type": "ACL_IPV4"
                            }
                        }
                    ]
                }
            },
            {
                "id": "ethernet 1/1/2",
                "config": {
                    "id": "ethernet 1/1/2"
                },
                "egress-acl-sets": {
                    "egress-acl-set": [
                        {
                            "set-name": "ext_acl1",
                            "type": "ACL_IPV4",
                            "config": {
                                "set-name": "ext_acl1",
                                "type": "ACL_IPV4"
                            }
                        }
                    ]
                }
            }
        ]
    }
}

DELETE : To delete a specific IPv4 ACL binding

URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F8/ingress-acl-sets/ingress-acl-set/ext3/ACL_IPV4
Request body: None
Response body: None

DELETE : To delete IPv4 ACL

URL: https://<host>/restconf/data/acl/acl-sets/acl-set/ext3/ACL_IPV4

Request body: None
Response body: None

GET method : To get or read specific IPv4 ACL configured in the system.

URL: https://<host>/restconf/data/acl/acl-sets/acl-set/ext3/ACL_IPV4
Request body: None
Response body: {
    "openconfig-acl:acl-set": [
        {
            "name": "ext3",
            "type": "openconfig-acl:ACL_IPV4",
            "config": {
                "name": "ext3",
                "type": "openconfig-acl:ACL_IPV4"
            },
            "state": {},
            "acl-entries": {
                "acl-entry": [
                    {
                        "sequence-id": 10,
                        "config": {
                            "sequence-id": 10
                        },
                        "state": {
                            "sequence-id": 10
                        },
                        "ipv4": {
                            "config": {
                                "source-address": "0.0.0.0",
                                "destination-address": "0.0.0.0",
                                "dscp": 0,
                                "protocol": 6,
                                "icx-openconfig-acl-aug:internal-priority-marking": {
                                    "internal-priority-marking": 7
                                },
                                "icx-openconfig-acl-aug:dscp-marking": {
                                    "dscp-marking": 10
                                }
                            },
                            "state": {
                               }
                        },
                        "transport": {
                            "config": {
                                "source-port": "0",
                                "destination-port": "0"
                            },
                            "state": {
                                }
                        },
                        "input-interface": {
                            "state": {},
                            "interface-ref": {
                                "state": {}
                            }
                        },
                        "actions": {
                            "config": {
                                "forwarding-action": "openconfig-acl:ACCEPT"
                            }   
                        }
                    }
                ]
            }
        }
    ]
}

GET method : To get or read specific ACL bound interface.

URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F5
Request Body: None
Response Body: {
    "openconfig-acl:interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/5",
                "config": {
                    "id": "ethernet 1/1/5"
                },
                "state": {},
                "interface-ref": {
                    "config": {
                        "interface": "ethernet 1/1/5"
                    },
                    "state": {}
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "ext3",
                            "type": "openconfig-acl:ACL_IPV4",
                            "config": {
                                "set-name": "ext3",
                                "type": "openconfig-acl:ACL_IPV4"
                            },
                            "state": {},
                            "acl-entries": {}
                        }
                    ]
                },
                "egress-acl-sets": {}
            }
        ]
    }
}

PATCH method for binding on ingress interface
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/15",
                "config": {
                    "id": "ethernet 1/1/15"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "device-IPv4",
                            "type": "ACL_IPV4",
                            "config": {
                                "set-name": "device-IPv4",
                                "type": "ACL_IPV4"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None
PATCH method for binding on an egress interface
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/12",
                "config": {
                    "id": "ethernet 1/1/12"
                },
                "egress-acl-sets": {
                    "egress-acl-set": [
                        {
                            "set-name": "device-IPv4",
                            "type": "ACL_IPV4",
                            "config": {
                                "set-name": "device-IPv4",
                                "type": "ACL_IPV4"
                            }
                        }
                    ]
                }
            }
        ]
    }
}

Response Body: None
To DELETE filter by sequence ID
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/<acl-name>/ACL_IPV4/acl-entries/acl-entry/10
PATCH method to create standard ACL and adding filter
URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
    "acl-sets": {
        "acl-set": [
            {
                "name": "acl-name",
                "type": "ACL_IPV4",
                "standard":true,
                "config": {
                    "name": "acl-name",
                    "type": "ACL_IPV4",
                    "standard":true
                },
                "acl-entries": {
                    "acl-entry": [
                        {
                            "sequence-id": 30,
                            "config": {
                                "sequence-id": 30
                            },
                            "ipv4": {
                                "config": {
                                    "source-address": "20.0.0.0/24"
                                   
                            }
                            },
                            "actions": {
                                "config": {
                                    "forwarding-action": "openconfig-acl:ACCEPT"
                                }
                            }
                        } 
                   ]
               }
           }
       ]
   }
}
Response Body: None
PATCH method (Binding on VLAN)
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
    "interfaces": {
        "interface": [
            {
                "id": "vlan 55",
                "config": {
                    "id": "vlan 55"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "101",
                            "type": "ACL_IPV4",
                            "config": {
                                "set-name": "101",
                                "type": "ACL_IPV4"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None

Supported HTTP operations for MAC ACL

To create MAC ACL and adding filters using PATCH method.

URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
    "acl-sets": {
        "acl-set": [
            {
                "name": "bj6",
                "type": "ACL_L2",
                "config": {
                    "name": "bj6",
                    "type": "ACL_L2"
                },
                "acl-entries": {
                    "acl-entry": [
                        {
                            "sequence-id": 100,
                            "config": {
                                "sequence-id": 100
                            },
                            "l2": {
                                "config": {
                                    "source-mac": "1111.2222.3333",
                                    "source-mac-mask": "1111.2222.3333",
                                    "destination-mac": "1111.2222.3333",
                                    "destination-mac-mask": "1111.2222.3333",
                                    "ethertype": 2048
                                }
                            },
                            "actions": {
                                "config": {
                                    "forwarding-action": "ACCEPT"
                                }
                            }
                        }
                    ]
                }
            }
        ]
    }
}

Response Body: None
                    

To create MAC ACL and adding filters using POST method.

URL: https://<host>/restconf/data/acl/acl-sets
{
    "acl-set": [
        {
            "name": "bj7",
            "type": "ACL_L2",
            "config": {
                "name": "bj7",
                "type": "ACL_L2"
            },
            "acl-entries": {
                "acl-entry": [
                    {
                        "sequence-id": 100,
                        "config": {
                            "sequence-id": 100
                        },
                        "l2": {
                            "config": {
                                "source-mac": "1111.2222.3333",
                                "source-mac-mask": "1111.2222.3333",
                                "destination-mac": "1111.2222.3333",
                                "destination-mac-mask": "1111.2222.3333",
                                "ethertype": 2048
                            }
                        },
                        "actions": {
                            "config": {
                                "forwarding-action": "ACCEPT"
                            }
                        }
                    }
               ]
            }
        }
    ]
}
Response Body: None

PATCH method (Binding on ingress interface)

URL: https://<host>/restconf/data/acl/interfaces
{
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/19",
                "config": {
                    "id": "ethernet 1/1/19"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "bj6",
                            "type": "ACL_L2",
                            "config": {
                                "set-name": "bj6",
                                "type": "ACL_L2"
                            }
                        }
                    ]
                }
            }
        ]
    }
}

POST method (Binding on an interface)

URL: https://<host>/restconf/data/acl
{
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/20",
                "config": {
                    "id": "ethernet 1/1/20"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "bj6",
                            "type": "ACL_L2",
                            "config": {
                                "set-name": "bj6",
                                "type": "ACL_L2"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None

PATCH method (Binding on a VLAN)

URL: https://<host>/restconf/data/acl/interfaces
{
    "interfaces": {
        "interface": [
            {
                "id": "vlan 100",
                "config": {
                    "id": "vlan 100"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "bj6",
                            "type": "ACL_L2",
                            "config": {
                                "set-name": "bj6",
                                "type": "ACL_L2"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None

To GET the configured MAC ACL "bj6".

URL: https://<host>/restconf/data/acl/acl-sets/acl-set/bj6/ACL_L2
Request Body: None
Response Body: {
    "openconfig-acl:acl-set": [
        {
            "name": "bj6",
            "type": "openconfig-acl:ACL_L2",
            "config": {
                "name": "bj6",
                "type": "openconfig-acl:ACL_L2"
            },
            "state": {},
            "acl-entries": {
                "acl-entry": [
                    {
                        "sequence-id": 100,
                        "config": {
                            "sequence-id": 100
                        },
                        "state": {},
                        "l2": {
                            "config": {
                                "source-mac": "1111.2222.3333",
                                "source-mac-mask": "1111.2222.3333",
                                "destination-mac": "1111.2222.3333",
                                "destination-mac-mask": "1111.2222.3333",
                                "ethertype": 2048
                            },
                            "state": {}
                        },
                        "input-interface": {
                            "state": {},
                            "interface-ref": {
                                "state": {}
                            }
                        },
                        "actions": {
                            "config": {
                                "forwarding-action": "openconfig-acl:ACCEPT"
                            },
                            "state": {}
                        }
                    }
                ]
            }
        }
    ]
}

To GET MAC ACL binding on an interface

URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F19
Request Body: None
Response Body: {
    "openconfig-acl:interface": [
        {
            "id": "ethernet 1/1/19",
            "config": {
                "id": "ethernet 1/1/19"
            },
            "state": {},
            "interface-ref": {
                "config": {
                    "interface": "ethernet 1/1/19"
                },
                "state": {}
            },
            "ingress-acl-sets": {
                "ingress-acl-set": [
                    {
                        "set-name": "bj6",
                        "type": "openconfig-acl:ACL_L2",
                        "config": {
                            "set-name": "bj6",
                            "type": "openconfig-acl:ACL_L2"
                        },
                        "state": {},
                        "acl-entries": {}
                    }
                ]
            },
            "egress-acl-sets": {}
        }
    ]
}
To DELETE a specific MAC ACL from an interface

URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F19/ingress-acl-sets/ingress-acl-set/bj6/ACL_L2
To DELETE MAC ACL "bj6"
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/bj6/ACL_L2

Supported HTTP Operations for IPv6 ACL

PATCH method to create IPv6 ACL and adding filter

URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
    "acl-sets": {
        "acl-set": [
            {
                "name": "acl_ipv61",
                "type": "ACL_IPV6",
                "config": {
                    "name": "acl_ipv61",
                    "type": "ACL_IPV6"
                },
                "acl-entries": {
                    "acl-entry": [
                        {
                            "sequence-id": 10,
                            "config": {
                                "sequence-id": 10
                            },
                            "ipv6": {
                                "config": {
                                    "source-address": "1000::10/120",
                                    "destination-address": "2000::10/100",
                                    "dscp": 0,
                                    "internal-priority-marking": {
                                    "internal-priority-marking" : 7
                                    },
                                    "dscp-marking": {
                                    "dscp-marking" : 10
                                    }
                                }
                            },
                            "actions": {
                                "config": {
                                    "forwarding-action": "ACCEPT"
                                }
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None

POST method to create IPv6 ACL and adding filter

URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
        "acl-set": [
            {
                "name": "acl_ipv62",
                "type": "ACL_IPV6",
                "config": {
                    "name": "acl_ipv62",
                    "type": "ACL_IPV6"
                },
                "acl-entries": {
                    "acl-entry": [
                        {
                            "sequence-id": 10,
                            "config": {
                                "sequence-id": 10
                            },
                            "ipv6": {
                                "config": {
                                    "source-address": "1000::10/120",
                                    "destination-address": "2000::10/64",
                                    "dscp":10,
                                    "internal-priority-marking": {
                                    "internal-priority-marking" : 7
                                    },
                                    "dscp-marking": {
                                    "dscp-marking" : 10
                                    }
                                }
                            },
                            "actions": {
                                "config": {
                                    "forwarding-action": "ACCEPT"
                                }
                            }
                        }
                    ]
                }
            }
        ]
    }
Response Body: None

PATCH method for binding on ingress and egress interface

URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/1",
                "config": {
                    "id": "ethernet 1/1/1"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "acl_ipv61",
                            "type": "ACL_IPV6",
                            "config": {
                                "set-name": "acl_ipv61",
                                "type": "ACL_IPV6"
                            }
                        }
                    ]
                }
            },
            {
                "id": "ethernet 1/1/7",
                "config": {
                    "id": "ethernet 1/1/7"
                },
                "egress-acl-sets": {
                    "egress-acl-set": [
                        {
                            "set-name": "acl_ipv61",
                            "type": "ACL_IPV6",
                            "config": {
                                "set-name": "acl_ipv61",
                                "type": "ACL_IPV6"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None

PATCH method for Ingress binding

URL: https://<host>/restconf/data/acl/interfaces
Request Body: 	{
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/7",
                "config": {
                    "id": "ethernet 1/1/7"
                },
                "ingress-acl-sets": {
                    "ingress-acl-set": [
                        {
                            "set-name": "acl_ipv62",
                            "type": "ACL_IPV6",
                            "config": {
                                "set-name": "acl_ipv62",
                                "type": "ACL_IPV6"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None

PATCH method for egress binding

URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
    "interfaces": {
        "interface": [
            {
                "id": "ethernet 1/1/12",
                "config": {
                    "id": "ethernet 1/1/12"
                },
                "egress-acl-sets": {
                    "egress-acl-set": [
                        {
                            "set-name": "device-IPv6",
                            "type": "ACL_IPV6",
                            "config": {
                                "set-name": "device-IPv6",
                                "type": "ACL_IPV6"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None

To DELETE IPv6 ACL bindings

URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F7/ingress-acl-sets/ingress-acl-set/acl_ipv62/ACL_IPV6

To DELETE IPv6 ACL

URL: https://<host>/restconf/data/acl/acl-sets/acl-set/acl_ipv61/ACL_IPV6

To GET specific IPv6 ACL configured in the system

URL: https://<host>/restconf/data/acl/acl-sets/acl-set/acl_ipv61/ACL_IPV6
Request Body: None
Response Body: {
 "openconfig-acl:acl-set": [
 {
 "name": "acl_ipv61",
 "type": "openconfig-acl:ACL_IPV6",
 "config": {
 "name": "acl_ipv61",
 "type": "openconfig-acl:ACL_IPV6"
 },
 "state": {},
 "acl-entries": {
 "acl-entry": [
 {
 "sequence-id": 10,
 "config": {
 "sequence-id": 10
 },
 "state": {
 },
 "ipv6": {
 "config": {
 "source-address": "1000::10/120",
 "destination-address": "2000::10/100",
 "dscp": 0,
 "protocol": 0,
 "icx-openconfig-acl-aug:internal-priority-marking": {
 "internal-priority-marking": 7
 },
 "icx-openconfig-acl-aug:dscp-marking": {
 "dscp-marking": 10
 }
 },
 "state": {
 }
 },
 "transport": {
 "config": {
 "source-port": "0",
 "destination-port": "0"
 },
 "state": {
 }
 },
 "input-interface": {
 "state": {},
 "interface-ref": {
 "state": {}
 }
 },
 "actions": {
 "config": {
 "forwarding-action": "openconfig-acl:ACCEPT"
 }
 }
 }
 ]
 }
 }
 ]
}

To GET all ACL binding interfaces

URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F5
Request Body: None
Response Body: {
 "openconfig-acl:interface": [
 {
 "id": "ethernet 1/1/5",
 "config": {
 "id": "ethernet 1/1/5"
 },
 "state": {},
 "interface-ref": {
 "config": {
 "interface": "ethernet 1/1/5"
 },
 "state": {}
 },
 "ingress-acl-sets": {
 "ingress-acl-set": [
 {
 "set-name": "ext3",
 "type": "openconfig-acl:ACL_IPV4",
 "config": {
 "set-name": "ext3",
 "type": "openconfig-acl:ACL_IPV4"
 },
 "state": {},
 "acl-entries": {}
 },
 {
 "set-name": "acl_ipv61",
 "type": "openconfig-acl:ACL_IPV6",
 "config": {
 "set-name": "acl_ipv61",
 "type": "openconfig-acl:ACL_IPV6"
 },
 "state": {},
 "acl-entries": {}
 }
 ]
 },
 "egress-acl-sets": {}
 }
 ]
}

To DELETE ACL filter using sequence ID

URL: https://<host>/restconf/data/acl/acl-sets/acl-set/device-ipv6/ACL_IPV6/acl-entries/acl-entry/10
PATCH method (Binding on VLAN)
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
    "interfaces": {
        "interface": [
            {
                "id": "vlan 55",
                "config": {
                    "id": "vlan 55"
                },
                "egress-acl-sets": {
                    "egress-acl-set": [
                        {
                            "set-name": "acl-name",
                            "type": "ACL_IPV6",
                            "config": {
                                "set-name": "acl-name",
                                "type": "ACL_IPV6"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
Response Body: None