Applying ACLs to rate limit inbound CPU traffic
Traffic policies can be included in ACLs and applied to incoming CPU traffic.
You can apply ACLs to the CPU on an ICX standalone unit or an ICX stack to filter or rate limit specific incoming traffic. For example, you can create ACLs to perform any of the following actions:
- Rate limit DHCP packets sent to the CPU
- Permit ICMP packets
- Permit packets from a known subnet
- Deny Telnet and SSH connections
Constraints on ACLs applied to inbound CPU traffic
The following restrictions pertain to ACLs applied to inbound CPU traffic:
- Only fixed rate limiting is supported for CPU ACLs.
- CPU ACLs cannot be applied on any other type of interface.
- Inbound traffic on the management port is also subject to the ACL applied to the CPU.
- In a stack, an ACL can be applied to the CPU of the active controller only. This does not create issues in a stack system during a failover because the ACL is applied to all stack units when it is bound to the active controller CPU.
- The maximum number of filters in an ACL applied to the CPU is 15.
- Standard IPv4 ACLs are not supported. IPv4 extended ACLs or IPv6 ACLs must be used.
- MAC ACLs are not supported.
- A DROP action is the only exceed-action allowed in a traffic policy applied to the CPU.
- ICX 7150 devices cannot bind an ACL containing a packet-based (packets-per-second) traffic policy to a CPU port. ICX 7150 devices can bind an ACL containing a byte-based traffic policy.
- Without a permit ip any any statement in an IPv4 ACL or a permit ipv6 any any statement in an IPv6 ACL, the ACL cannot be bound to a CPU port.
- The deny any any statement is not supported for ACLs applied to the CPU.
- ACLs applied to the CPU do not support implicit filters, such as deny any any, characteristic of other ACLs applied on ICX devices. In other words, it is not possible to block all traffic to the CPU.
- PPS (packet based) Traffic policy with ACL on CPU port feature is not supported on ICX 7150-48P, ICX 7150-48ZP, and ICX 7150-C08 devices.
- In TCP and UDP filters, only the equal option (eq) is supported.
- Accounting, mirroring, and logging are not supported in ACLs applied to the CPU.
Unsupported protocols and options
The following protocols and options are not supported in IPv4 ACLs applied to the CPU:
- esp
- gre
- 802.1p-and-internal-marking
- 802.1p-priority-marking
- 802.1p-priority-matching
- dscp-marking
- dscp-matching
- internal-priority-marking
- precedence
- tos
The following protocols and options are not supported in IPv6 ACLs applied to the CPU: