ACL- Related Changes When Upgrading to FastIron 08.0.95

The following table offers details regarding a FastIron 08.0.95 image upgrade with respect to ACLs.

Functionality FastIron 08.0.92 FastIron 08.0.95
ACL MIB
  • ACL MIBs are indexed using ACL ID.
  • Supported MIBs for ACLs bound to VE and interfaces only.
  • ACL MIBs are indexed using ACL name.
  • MIB support for ACLs bound to VLAN, LAG, and VPORT (VLAN + port).
  • MIB is not supported for ACLs on VE.
  • You must switch to new ACL MIBs for RUCKUS ICX devices running FastIron 08.0.95 and later releases.
IPv4 ACL filter A number of well-known protocol name options are supported. A number of well-known TCP or UDP port name options are supported. Well-known protocol name options of an IPv4 Extended ACL filter configuration are reduced to a few commonly used names. However, any protocol configuration is allowed by specifying the corresponding protocol number.

TCP or UDP application port name options of an IPv4 Extended ACL filter configuration are reduced to a few commonly used application port names. However, any application can be configured by specifying the corresponding port number.

IPv6 ACL filter A number of well-known protocol name options are supported. A number of well-known TCP or UDP port name options are supported. Well-known protocol name options of an IPv6 ACL filter configuration are reduced to a few commonly used names. However, any protocol configuration is allowed by specifying the corresponding protocol number.

TCP or UDP application port name options while configuring an IPv6 ACL filter are reduced to a few commonly used application port names. However, any application can be configured by specifying the corresponding port number.

MAC filter configuration MAC filter configuration using the mac filter command is supported. The MAC filter group configuration is auto converted to a named MAC ACL in FastIron 08.0.95. The ACL logging or mirroring or accounting configuration in the MAC filter is migrated seamlessly.

The mac filter command at the global level and the mac filter-group command at the interface level are deprecated and replaced by the mac access-list command with underlying filter statements beginning in FastIron 08.0.95.

The accounting configuration for MAC filters that are not bound to any interface will be lost during upgrade and must be configured again for any resulting MAC ACL.

IPv4 ACL binding The following configurations are supported in FastIron 08.0.92:
  • ACL binding at the VE level in a router image.
  • The per-VLAN ACL configuration in a switch image.
  • ACL binding at the selective port of a VE in a router image.
ACL binding to a VLAN on both the switch and router image is supported. The ACL binding configuration at the VE level is converted to a VLAN configuration. The ACL binding on the per- vlan and selective port of a VE is converted to the binding of a selective port in a VLAN.
IPv6 ACL binding ACL binding at the VE level in a router image is supported. The binding of an ACL to a VLAN in both the switch and router image is supported. The ACL binding configuration at the VE level is converted to a VLAN configuration. Beginning with FastIron 08.0.95, the binding command ipv6 traffic-filter is changed to the ipv6 access-group command.
MAC filter binding MAC filter binding is supported. The MAC filter binding group forms a MAC ACL and is bound to an interface, much like an IP ACL. The MAC filter functionality remains intact.

Beginning with FastIron 08.0.95, the mac-filter group command is modified to the mac access-group command.

ACL Accounting Accounting is enabled at the ACL level for IPv4 and IPv6 ACLs, and enabled at the filter level for MAC ACLs. Accounting is configurable at an ACL level. Accounting is applied for all the filters on all interfaces to which the ACL is bound. ACL accounting is enabled by default. The enable accounting command has been introduced. The auto-migration uses the new enable accounting command.
ACL Logging Logging is enabled at the interface level for IPv4 ACLs and at the ACL level for IPv6 ACLs, and enabled at filter and filter-group level for MAC ACLs. Logging is configurable only at the binding level using the logging enable command in conjunction with the log keyword at the filter level for IPv4, IPv6, and MAC ACLs. If ACL logging is enabled in an earlier release, ACL logging is enabled automatically under resulting ACL binding after the upgrade process.
DSCP or PCP Remarking The DSCP or PCP remarking configuration at the global level is supported. In FastIron 08.0.95, the DSCP or PCP remarking configuration at the global level is not supported, even though it was configured in a previous release. You can configure DSCP or PCP at the interface level, where DSCP actions will be merged with the user ACLs bound on the interface.
Per-port-per-VLAN The per-port-per-VLAN configuration is supported. The enable acl-per-port-per-vlan command is deprecated in FastIron 08.0.95. By default, all ports are enabled with per-port-per-VLAN.
ACL Policy The acl-policy command and the suppress-acl-seq commands are supported. These commands are used during the downgrade process to FastIron 08.0.50 or releases prior to FastIron 08.0.50. The acl-policy command and suppress-acl-seq commands are deprecated in FastIron 08.0.95.
ACL on ARP ACL ID is not mandatory. In FastIron 08.0.95 release,an ACL ID is mandatory to configure an ACL on ARP. Enter an ACL number to specify the ACL to be used for filtering. If you have configured an ACL ARP without an ACL ID in an earlier release, the system will lose the configuration during the upgrade process.
ND-packet hop-limit check The ND hop-limit configuration is configured using the enable nd hop-limit command under IPv6 ACL. The ND hop-limit functionality is enabled by default. The ipv6 nd ra-hop-limit and enable nd hop-limit commands are deprecated. Checking for ND packets with a hop limit less than 255 helps protect against denial of service (DoS) attacks. The enable nd-hop-limit command is deprecated in FastIron 08.0.95.
Traffic Policy The cir keyword is not supported in the configuration. The traffic-policy rate-limit adaptive and traffic-policy rate-limit fixed commands are modified to add a new cir keyword. The rate can be specified as either packets or bytes.
DDoS DDoS configuration on a virtual Ethernet interface is supported. DDoS configuration at the VLAN level in a router image is allowed. During the upgrade process, the DDoS configuration at the VE level in a router image is applied to the VLAN in FastIron 08.0.95.
DDoS configuration on a tagged or dual mode interface in a switch image DDOS configuration is supported on a virtual Ethernet interface on router images and on tagged or dual mode interfaces in a switch image in pre-08.0.95 release. During the upgrade process,DDOS configuration under tagged or dual mode interface in a switch image will be lost. You have to re-configure the same configuration under VLAN in switch images in 08.0.95 release.
DHCPv4 and DHCPv6 snooping on VLANs of a VLAN group DHCPv4 or DHCPv6 snooping must be enabled on all the VLANs in a VLAN group. DHCPv4 and DHCPv6 snooping on VLANs of a VLAN group is not supported. You will lose the configuration during the upgrade process.
IP Source Guard (IPSG) IPSG configuration at the VE level in a router image, and at per-port-per-VLAN in a switch image is supported. IPSG configuration at the VE level and at per-port-per-VLAN will be migrated to a VLAN with the selective port option.
IPSG and ingress IPv4 User ACL (UACL) for the same port IPSG and ingress IPv4 UACL configuration for the same port can be configured together at the interface level or at the VE level or per-vlan level. If a port has both IPSG and UACL configuration together at any level, the upgrade process does not take place, and you will lose the UACL configuration. A warning message is displayed for the problem during bootup in FastIron 08.0.95 and later releases.
System default values and system-max commands for Static DAI and DHCP snooping The system default values for Static Dynamic ARP Inspection (DAI) entries is 512 and for DHCP snooping is 8192. However, these default values can be changed for Static DAI and DHCP snooping using the system-max max static-inspect-arp-entries and system-max max max-dhcp-snoop-entries commands, respectively. The system-max commands for Static DAI and DHCP snooping are deprecated beginning in FastIron 08.0.95, and the configurations are lost during the upgrade process.

The new system default value for Static DAI is 6000 and for DHCP snooping is 32768.

DHCP snooping flash update interval configuration The ip dhcp snooping flash-update-interval command is supported. The ip dhcp snooping flash-update-interval command is deprecated beginning in FastIron 08.0.95 and the system will lose the configuration during the upgrade process.
System default values The system default value depends upon the hardware. The system default value depends upon the hardware. System default values for the ICX 7550 include the following values:

Maximum configurable filters the device supports (IPv4 and IPv6 ACLs): 8192

Maximum configurable filters per ACL (either IPv4 or IPv6 ACLs): 2048

MAC filter statements per ACL: 256

MAC filter statements per stack: 3072

Authentication filter MAC filter ID can be passed to the authentication auth-filter command configured in interface configuration mode

The authentication auth-filter command is deprecated and replaced by the authentication filter command. A MAC ACL filter has to be provided to this command instead of MAC ACLs. The MAC ACL filter supports source MAC address filters only.

Maximum VLAN support with User ACL clients There is no limit. FastIron 08.0.95 supports up to 512 VLANs to bind different clients having the same functionality. For example, features such as IPSG, DAI, and DHCP snooping can be enabled on 512 VLANs. A functionality enabled on more than 512 VLANs will lose the configuration during migration.
DHCP snooping or DAI or IPv6 Network Interface Identifier enabled on VLAN. DHCP snooping or DAI or Network Interface Identifier enabled on a VLAN without ports does not allocate hardware resources. DHCP snooping or DAI or Network Interface Identifier enabled on a VLAN without ports allocates hardware resources for each VLAN for each Control Bridge (CB) unit. If TCAM space is full, enabling DHCP snooping or DAI or NDI on a VLAN without ports causes functionality failures during migration.
DHCP snooping database The DHCP snooping database file name format is dhcpsnoop.db. The DHCP snooping database file name format is icx_dhcp_snoop.db. Remove all entries from the DHCP binding database using the clear dhcp and clear ipv6 dhcp6 snoop commands before the downgrade process to a release prior to FastIron 08.0.95.
Note: On an ICX 7850 device, if you migrate to FastIron 08.0.95 or a later release from a FastIron 08.0.92 configuration that contains an IPv4 egress ACL applied to a virtual interface, the two TCAM rules originally programmed for the ACL (one ACL rule and one implicit deny rule) are programmed as four TCAM rules in the target release configuration, where the ACL will be applied at the VLAN level; that is, two rules for the ACL and two rules for the implicit deny rule.

On an ICX 7850 device, if you migrate from FastIron 08.0.92 to FastIron 08.0.95 or a later release, the rules created for an IPv6 egress ACL applied to a virtual interface multiply. For example, if you created the original IPv6 egress ACL with one rule, the ACL is programmed as four rules in TCAM for the FastIron 08.0.92 configuration; that is, one IPv6 ACL rule and three implicit rules. In the resulting configuration for the target release, the IPv6 ACL is applied at the VLAN level, and a total of eight rules will be created in TCAM; that is, two ACL rules and six implicit rules.