Layer 3 ACL Overview

Layer 3 (IPv4 and IPv6) access control lists (ACLs) permit or deny packets according to rules included in the ACLs.

Note: ACL configuration has changed significantly in FastIron release 08.0.95. Refer to the RUCKUS FastIron Software Upgrade Guide for additional information on the changes.

Note: ACLs cannot be configured from the web in FastIron release 08.0.95.

When a packet is received or sent, the device compares its header fields against the rules in applied ACLs. This comparison is done sequentially, in the order the rules are entered or on the sequence numbers you specify. Based on the comparison, the device either forwards or drops the packet.

ACLs include the following benefits:

  • Providing security and traffic management
  • Monitoring network and user traffic
  • Saving network resources by classifying traffic
  • Protecting against Denial of Service (DoS) attacks
  • Reducing debug output

Because applied ACLs are programmed into the Content Addressable Memory (CAM), packets are permitted or denied in the hardware, without sending the packets to the CPU for processing.

Layer 3 ACLs are implemented using the following flow:

  1. Create the ACL, using the ip access-list or ipv6 access-list command.
  2. Define permit and deny rules, using the deny and permit commands. (A sequence number is assigned automatically to each rule, based on the order of entry.)
  3. Apply the ACL to one or more interfaces or VLANs, using the relevant command:
    • IPv4: ip access-group
    • IPv6: ipv6 access-group

Layer 3 ACLs are supported on all ICX device physical interface types and LAGs.

Named ACLs and numbered ACLs are supported for IPv4 ACLs. IPv6 ACLs are named. Named ACLs must begin with an alphabetical character and can contain up to 47 alphanumeric characters.

Added information for FI-266037 regardng the double quotes. This applied to 09.0.10e, 08.0.95j, and 10.0.00

Special characters, such as <, >, and &, are not allowed, except for double quotes that are allowed in the following software release steams from these specifc patch releases:

  • FastIron 08.0.95j and later

Note: For Layer 2 filtering, refer to MAC ACLs.

Note: For ACLs under Flexible authentication, refer to Dynamic ACLs in Authentication.