IPv4 ACL Configuration Guidelines

  • Flow-based ACLs are not supported on RUCKUS ICX devices.
  • Inbound ACLs apply to all traffic, including control traffic. By default, outbound ACLs are not applied to traffic generated by the CPU. To enable the application of outbound ACLs to CPU traffic, use the enable egress-acl-on-cpu-traffic command. Refer to Applying Egress ACLs to Control (CPU) Traffic for details.
  • The RUCKUS ICX ACL implementation supports only one ACL per port or VLAN. The ACL can contain multiple entries (rules). For example, hardware-based ACLs do not support ACL101 and ACL102 on port 1/1/1 or VLAN 100, but hardware-based ACLs do support ACL101 containing multiple entries. If a user tries to apply a second ACL on a port or VLAN, the second ACL will replace the current ACL.
  • Inbound ACLs and outbound ACLs can be configured on the same port or VLAN.
  • By default, the first fragment of a fragmented packet received by a FastIron device is permitted or denied using the ACLs, but subsequent fragments of the same packet are forwarded in hardware. Generally, denying the first fragment of a packet is sufficient because a transaction cannot be completed without the entire packet.
  • ACLs are supported on member ports of a VLAN on which DHCP snooping and Dynamic ARP Inspection (DAI) are enabled. However, IP source guard and ACLs are not supported together at the port level, at the VLAN level, or across levels.
  • Outbound ACLs cannot be configured through a RADIUS server as dynamic or user-based ACLs. However, outbound ACLs can still be configured with MAC authentication or 802.1X authentication enabled, as they are configured in different directions.
  • On all platforms, ACL support for switched inbound and outbound traffic is enabled by default.
  • IPv4 ACLs are supported on tagged ports.
  • An outbound IPv4 ACL with a rule pertaining to ESP protocol does not match ESP packets with IPv4 headers on ICX 7550 or ICX 7850 devices.
  • You can apply an ACL to a port that has TCP SYN attack protection or ICMP smurf attack protection, or both, enabled.
  • When forming LAGs, make sure that no ACLs are currently applied to the relevant physical interfaces.
  • When using host names in ACL filter configurations, a TCAM entry will be programmed with the first IP address resolved through DNS service. Any further updates to DNS entries do not automatically update TCAM.
  • It is not possible to configure conflicting ACL filters. When an ACL filter is configured, if the sequence number already exists, or the sequence number is not specified explicitly and all the filter parameters match with an existing filter but the action does not match, the following error message is displayed:

    Error: ACL operation failed for ACL ipv4-test1 since following conflicting filter entry already exists. Please use explicit sequence number to override this error.

  • ACL mirroring is not supported for outbound ACLs.