IPv4 ACL Configuration Guidelines

  • Flow-based ACLs are not supported on FastIron devices.
  • Inbound ACLs apply to all traffic, including control traffic. By default, outbound ACLs are not applied to traffic generated by the CPU. To enable the application of outbound ACLs to CPU traffic, use the enable egress-acl-on-cpu-traffic command. Refer to Applying Egress ACLs to Control (CPU) Traffic for details.
  • The RUCKUS ICX ACL implementation supports only one ACL per port or VLAN. The ACL can contain multiple entries (rules). For example, hardware-based ACLs do not support ACL101 and ACL102 on port 1/1/1 or VLAN 100, but hardware-based ACLs do support ACL101 containing multiple entries. If a user tries to apply a second ACL on a port or VLAN, the second ACL will replace the current ACL.
  • Inbound ACLs and outbound ACLs can be configured on the same port or VLAN.
  • By default, the first fragment of a fragmented packet received by a FastIron device is permitted or denied using the ACLs, but subsequent fragments of the same packet are forwarded in hardware. Generally, denying the first fragment of a packet is sufficient because a transaction cannot be completed without the entire packet.
  • ACLs are supported on member ports of a VLAN on which DHCP snooping and Dynamic ARP Inspection (DAI) are enabled. Also, IP source guard and ACLs are supported together on the same port, as long as both features are configured at the port level or VLAN level. However, IP source guard and ACLs are not supported on the same port if one is configured at the port level and the other is configured at the per-port-per-VLAN level.
  • Outbound ACLs cannot be configured through a RADIUS server as dynamic or user-based ACLs. However, outbound ACLs can still be configured with MAC authentication or 802.1X authentication enabled, as they are configured in different directions.
  • On all platforms—in the router image—ACL support for switched inbound and outbound traffic is enabled by default.
  • IPv4 ACLs are supported on tagged ports in Layer 3 software images.
  • You can apply an ACL to a port that has TCP SYN attack protection or ICMP smurf attack protection, or both, enabled.
  • When forming LAGs, make sure that no ACLs are currently applied to the relevant physical interfaces.
  • When using host names in ACL filter configurations, a TCAM entry will be programmed with the first IP address resolved through DNS service. Any further updates to DNS entries do not automatically update TCAM.
  • In a Campus Fabric network, avoid updating ACLs while PE units are being hot swapped. Any ACL updates under these circumstances may produce unexpected results.
  • It is not possible to configure conflicting ACL filters. When an ACL filter is configured, if the sequence number already exists, or the sequence number is not specified explicitly and all the filter parameters match with an existing filter but the action does not match, the following error message is displayed:

    Error: ACL operation failed for ACL ipv4-test1 since following conflicting filter entry already exists. Please use explicit sequence number to override this error.

  • ACL mirroring is not supported for outbound ACLs.