Layer 3 ACL Overview
When a packet is received or sent, the device compares its header fields against the rules in applied ACLs. This comparison is done sequentially, in the order the rules are entered or on the sequence numbers you specify. Based on the comparison, the device either forwards or drops the packet.
ACLs include the following benefits:
- Providing security and traffic management
- Monitoring network and user traffic
- Saving network resources by classifying traffic
- Protecting against Denial of Service (DoS) attacks
- Reducing debug output
Because applied ACLs are programmed into the Content Addressable Memory (CAM), packets are permitted or denied in the hardware, without sending the packets to the CPU for processing.
Layer 3 ACLs are implemented using the following flow:
- Create the ACL, using the
ip access-listoripv6 access-listcommand. - Define permit and deny rules, using the
denyandpermitcommands. (A sequence number is assigned automatically to each rule, based on the order of entry.) - Apply the ACL to one or more interfaces or VLANs, using the relevant command:
Layer 3 ACLs are supported on all ICX device physical interface types and LAGs.
Named ACLs and numbered ACLs are supported for IPv4 ACLs. IPv6 ACLs are named. Named ACLs must begin with an alphabetical character and can contain up to 47 alphanumeric characters.
Special characters, such as <, >, and &, are not allowed, except for double quotes that are allowed in the following software release steams from these specifc patch releases: