Applying ACLs to rate limit inbound CPU traffic

Traffic policies can be included in ACLs and applied to incoming CPU traffic.

You can apply ACLs to the CPU on an ICX standalone unit or stack to filter or rate limit specific incoming traffic. For example, you can create CPUs to perform any of the following actions:

  • rate limit DCHP packets sent to the CPU
  • permit ICMP packets
  • permit packets from a known subnet
  • deny Telnet and SSH connections

Constraints on ACLs applied to CPU traffic

Bear in the mind the following constraints when applying ACLs to CPU traffic:

  • Only fixed rate limiting is supported for CPU ACLs.
  • CPU ACLs cannot be applied on any other type of interface.
  • Inbound traffic on the management port is also subject to the ACL applied to the CPU.
  • In a stack, an ACL can be applied to the CPU of the active controller only.
  • The maximum number of filters in an ACL applied to the CPU is 15.
  • Standard IPv4 ACLs are not supported. IPv4 extended ACLs or IPv6 ACLs must be used.
  • MAC ACLs are not supported.
  • A DROP action is the only exceed-action allowed in a traffic policy applied to the CPU.
  • In an ICX device that has two packet processors, for example, ICX 7450-32P, ICX 7450-48P, or ICX 7150-48P devices, an ACL applied on the CPU port is applied in both packet processors.

  • The deny any any statement is not supported for ACLs applied to the CPU.
  • ACLs applied to the CPU do not support implicit filters, such as deny any any, characteristic of other ACLs applied on ICX devices. In other words, it is not possible to block all traffic to the CPU.
  • In TCP and UDP filters, only the equal option ‘eq’ is supported.
  • Accounting, mirroring, and logging are not supported in ACLs applied to the CPU.

Unsupported protocols and options

The following protocols and sub-options are not supported in IPv4 ACLs applied to the CPU:

  • esp
  • gre
  • 802.1p-and-internal-marking
  • 802.1p-priority-marking
  • 802.1p-priority-matching
  • dscp-marking
  • dscp-matching
  • internal-priority-marking
  • precedence
  • tos

The following protocols and sub-options are not supported in IPv6 ACLs applied to the CPU:

  • ahp
  • esp
  • sctp
  • 802.1p-priority-marking
  • 802.1p-priority-matching
  • dscp-marking
  • dscp-matching
  • fragments
  • internal-priority-marking
  • routing
  • precedence, gt, lt, neq