| ACL MIB |
- ACL MIBs are
indexed using ACL ID.
- Supported MIBs for
ACLs bound to VE and interfaces only.
|
- ACL MIBs are
indexed using ACL name.
- MIB support for
ACLs bound to VLAN, LAG, and VPORT (VLAN + port).
- MIB is not
supported for ACLs on VE.
- You must switch to
new ACL MIBs for RUCKUS ICX devices running FastIron 08.0.95
and later releases.
|
| IPv4 ACL filter |
A number of well-known protocol name
options are supported. A number of well-known TCP or UDP port name
options are supported. |
Well-known protocol name options of
an IPv4 Extended ACL filter configuration are reduced to a few
commonly used names. However, any protocol configuration is allowed
by specifying the corresponding protocol number. TCP or UDP
application port name options of an IPv4 Extended ACL filter
configuration are reduced to a few commonly used application
port names. However, any application can be configured by
specifying the corresponding port number.
|
| IPv6 ACL filter |
A number of well-known protocol name
options are supported. A number of well-known TCP or UDP port name
options are supported. |
Well-known protocol name options of
an IPv6 ACL filter configuration are reduced to a few commonly used
names. However, any protocol configuration is allowed by specifying
the corresponding protocol number. TCP or UDP
application port name options while configuring an IPv6 ACL
filter are reduced to a few commonly used application port
names. However, any application can be configured by specifying
the corresponding port number.
|
| MAC filter configuration |
MAC filter configuration using the
mac
filter command is supported. |
The MAC filter group configuration is
auto converted to a named MAC ACL in FastIron 08.0.95. The ACL
logging or mirroring or accounting configuration in the MAC filter
is migrated seamlessly. The mac
filter command at the global level and the
mac
filter-group command at the interface level are
deprecated and replaced by the mac
access-list command with underlying filter
statements beginning in FastIron 08.0.95. The accounting
configuration for MAC filters that are not bound to any
interface will be lost during upgrade and must be configured
again for any resulting MAC ACL.
|
| IPv4 ACL binding |
The following configurations are
supported in FastIron 08.0.92:- ACL binding at the VE level in a router image.
- The per-VLAN ACL configuration in a switch image.
- ACL binding at the selective port of a VE in a router
image.
|
ACL binding to a VLAN on both the
switch and router image is supported. The ACL binding configuration
at the VE level is converted to a VLAN configuration. The ACL
binding on the per- vlan and selective port of a VE is converted to
the binding of a selective port in a VLAN. |
| IPv6 ACL binding |
ACL binding at the VE level in a
router image is supported. |
The binding of an ACL to a VLAN in
both the switch and router image is supported. The ACL binding
configuration at the VE level is converted to a VLAN configuration.
Beginning with FastIron 08.0.95, the binding command ipv6
traffic-filter is changed to the ipv6
access-group command. |
| MAC filter binding |
MAC filter binding is supported. |
The MAC filter binding group forms a
MAC ACL and is bound to an interface, much like an IP ACL. The MAC
filter functionality remains intact. Beginning with
FastIron 08.0.95, the mac-filter
group command is modified to the mac
access-group command.
|
| ACL Accounting |
Accounting is enabled at the ACL
level for IPv4 and IPv6 ACLs, and enabled at the filter level for
MAC ACLs. |
Accounting is configurable at an ACL
level. Accounting is applied for all the filters on all interfaces
to which the ACL is bound. ACL accounting is enabled by default. The
enable
accounting command has been introduced. The
auto-migration uses the new enable accounting
command. |
| ACL Logging |
Logging is enabled at the interface
level for IPv4 ACLs and at the ACL level for IPv6 ACLs, and enabled
at filter and filter-group level for MAC ACLs. |
Logging is configurable only at the
binding level using the logging
enable command in conjunction with the log keyword
at the filter level for IPv4, IPv6, and MAC ACLs. If ACL logging is
enabled in an earlier release, ACL logging is enabled automatically
under resulting ACL binding after the upgrade process. |
| DSCP or PCP Remarking |
The DSCP or PCP remarking
configuration at the global level is supported. |
In FastIron 08.0.95, the DSCP or PCP
remarking configuration at the global level is not supported, even
though it was configured in a previous release. You can configure
DSCP or PCP at the interface level, where DSCP actions will be
merged with the user ACLs bound on the interface. |
| Per-port-per-VLAN |
The per-port-per-VLAN configuration
is supported. |
The enable
acl-per-port-per-vlan command is deprecated in
FastIron 08.0.95. By default, all ports are enabled with
per-port-per-VLAN. |
| ACL Policy |
The acl-policy command and the suppress-acl-seq commands are supported. These
commands are used during the downgrade process to FastIron 08.0.50
or releases prior to FastIron 08.0.50. |
The acl-policy command and suppress-acl-seq commands are deprecated in FastIron
08.0.95. |
| ACL on ARP |
ACL ID is not mandatory. |
In FastIron 08.0.95 release,an ACL
ID is mandatory to configure an ACL on ARP. Enter an ACL number to
specify the ACL to be used for filtering. If you have configured an
ACL ARP without an ACL ID in an earlier release, the system will
lose the configuration during the upgrade process. |
| ND-packet hop-limit check |
The ND hop-limit configuration is
configured using the enable nd
hop-limit command under IPv6 ACL. |
The ND hop-limit functionality is
enabled by default. The ipv6 nd
ra-hop-limit and enable nd
hop-limit commands are deprecated. Checking for ND
packets with a hop limit less than 255 helps protect against denial
of service (DoS) attacks. The enable
nd-hop-limit command is deprecated in FastIron
08.0.95. |
| Traffic Policy |
The cir keyword
is not supported in the configuration. |
The traffic-policy
rate-limit adaptive and traffic-policy
rate-limit fixed commands are modified to add a new cir keyword.
The rate can be specified as either packets or bytes. |
| DDoS |
DDoS configuration on a virtual
Ethernet interface is supported. |
DDoS configuration at the VLAN level
in a router image is allowed. During the upgrade process, the DDoS
configuration at the VE level in a router image is applied to the
VLAN in FastIron 08.0.95. |
| DDoS configuration on a tagged or dual mode
interface in a switch image |
DDOS configuration is supported on a virtual
Ethernet interface on router images and on tagged or dual mode
interfaces in a switch image in pre-08.0.95 release. |
During the upgrade process,DDOS configuration under tagged or dual mode
interface in a switch image will be lost. You have to re-configure
the same configuration under VLAN in switch images in 08.0.95
release. |
| DHCPv4 and DHCPv6 snooping on VLANs
of a VLAN group |
DHCPv4 or DHCPv6 snooping must be
enabled on all the VLANs in a VLAN group. |
DHCPv4 and DHCPv6 snooping on VLANs
of a VLAN group is not supported. You will lose the configuration
during the upgrade process. |
| IP Source Guard (IPSG) |
IPSG configuration at the VE level in a
router image, and at per-port-per-VLAN in a switch image is
supported. |
IPSG configuration at the VE level
and at per-port-per-VLAN will be migrated to a VLAN with the
selective port option. |
| IPSG and ingress IPv4 User ACL (UACL)
for the same port |
IPSG and ingress IPv4 UACL
configuration for the same port can be configured together at the
interface level or at the VE level or per-vlan level. |
If a port has both IPSG and UACL
configuration together at any level, the upgrade process does not
take place, and you will lose the UACL configuration. A warning
message is displayed for the problem during bootup in FastIron
08.0.95 and later releases. |
System default values and system-max commands for Static DAI and DHCP snooping |
The system default values for Static
Dynamic ARP Inspection (DAI) entries is 512 and for DHCP snooping is
8192. However, these default values can be changed for Static DAI
and DHCP snooping using the system-max max
static-inspect-arp-entries and system-max max
max-dhcp-snoop-entries commands, respectively. |
The system-max commands for Static DAI and DHCP snooping
are deprecated beginning in FastIron 08.0.95, and the configurations
are lost during the upgrade process. The new system
default value for Static DAI is 6000 and for DHCP snooping is
32768.
|
| DHCP snooping flash update interval
configuration |
The ip dhcp snooping
flash-update-interval command is supported. |
The ip dhcp snooping
flash-update-interval command is deprecated beginning
in FastIron 08.0.95 and the system will lose the configuration
during the upgrade process. |
| System default values |
The system default value depends upon
the hardware. |
The system default value depends
upon the hardware. System default values for the ICX 7550 include
the following values: Maximum
configurable filters the device supports (IPv4 and IPv6 ACLs):
8192 Maximum
configurable filters per ACL (either IPv4 or IPv6 ACLs): 2048 MAC filter
statements per ACL: 256 MAC filter
statements per stack: 3072
|
| Authentication filter |
MAC filter ID can be passed to the
authentication auth-filter command configured in
interface configuration mode |
The authentication auth-filter command is deprecated
and replaced by the authentication filter command. A MAC ACL filter
has to be provided to this command instead of MAC ACLs. The MAC
ACL filter supports source MAC address filters only.
|
| Maximum VLAN support with User ACL
clients |
There is no limit. |
FastIron 08.0.95 supports up to 512
VLANs to bind different clients having the same functionality. For
example, features such as IPSG, DAI, and DHCP snooping can be
enabled on 512 VLANs. A functionality enabled on more than 512 VLANs
will lose the configuration during migration. |
| DHCP snooping or DAI or IPv6 Network Interface Identifier
enabled on VLAN. |
DHCP snooping or DAI or Network
Interface Identifier enabled on a VLAN without ports does not
allocate hardware resources. |
DHCP snooping or DAI or Network
Interface Identifier enabled on a VLAN without ports allocates
hardware resources for each VLAN for each Control Bridge (CB) unit.
If TCAM space is full, enabling DHCP snooping or DAI or NDI on a
VLAN without ports causes functionality failures during migration.
|
| DHCP snooping database |
The DHCP snooping database file name
format is dhcpsnoop.db. |
The DHCP snooping database file name
format is icx_dhcp_snoop.db. Remove all entries from the DHCP binding
database using the clear
dhcp and clear ipv6 dhcp6
snoop commands before the downgrade process to a
release prior to FastIron 08.0.95. |