Configuration Guidelines for Dynamic ACLs
The following restrictions apply to dynamic IPv4 ACLs and IPv6 ACLs:
- Dynamic ACLs are supported only for inbound traffic.
- For dynamic ACLs, the ND packet hop-limit check is supported only for inbound traffic.
- By default, Flexible authentication supports hop-limit checks for the following types of packets using implicit rules:
- If the RADIUS-provided egress ACL contains an explicit "permit" filter for ND, NS, RS, or RA packets, the hop-limit check is still performed on outbound traffic.
- The name in the Filter-Id attribute is case-sensitive.
- When an ACL is created, make sure to immediately add at least one rule to the ACL.
- IPv4 ACLs can be used in Web authentication. IPv6 ACLs are not supported for Web authentication.
- Both dynamically assigned inbound and outbound IPv4 ACLs and IPv6 ACLs can be applied together. If both IPv4 ACLs and IPv6 ACLs are applied, only one inbound type or one outbound type of each filter is allowed.
- A maximum of one IP ACL per client can be configured for IPv4 inbound, IPv4 outbound, IPv6 inbound, and IPv6 outbound on an interface.
- Static ACLs are not supported on the 802.1X authentication-enabled or the MAC authentication-enabled port.
- Concurrent operation of dynamic IP ACLs and static IP ACLs is not supported.
- Dynamic IP ACL assignment with 802.1X is not supported in conjunction with any of the following features:
- Deletion of an ACL ID is not recommended when ACLs are used by Flexible authentication sessions or Web authentication sessions.
- Dynamic ACLs support either one IPv4 address or up to four IPv6 addresses.
- Changing an ACL ID in the RADIUS user profile is not supported during reauthentication.