Access Control Lists

Layer 3 (IPv4 and IPv6) access control lists (ACLs) permit or deny packets according to rules included in the ACLs. When a packet is received or sent, the device compares its header fields against the rules in applied ACLs. This comparison is done sequentially, in the order the rules are entered or on the sequence numbers you specify. Based on the comparison, the device either forwards or drops the packet. Only a minimal number of ACL configurations are supported in the web interface.

Regarding the range of filtering options, there are two types of IPv4 ACLs:

  • Standard ACLs: Permit or deny traffic according to source address only.
  • Extended ACLs: Permit or deny traffic according to source and destination addresses, as well as other parameters. For example, in an extended ACL, you can also filter by one or more of the following parameters:
    • Port name or number
    • Protocol (for example, TCP or UDP)

ACLs include the following benefits:

  • Providing security and traffic management
  • Monitoring network and user traffic
  • Saving network resources by classifying traffic
  • Protecting against Denial of Service (DoS) attacks
  • Reducing debug output

Because applied ACLs are programmed into the Content Addressable Memory (CAM), packets are permitted or denied in the hardware, without sending the packets to the CPU for processing. Named ACLs and numbered ACLs are supported for IPv4 ACLs. IPv6 ACLs are named. Named ACLs must begin with an alphabetical character and can contain up to 47 alphanumeric characters.