Applying ACLs to Rate Limit Inbound CPU Traffic
Traffic policies can be included in ACLs and applied to incoming CPU traffic.
You can apply ACLs to the CPU on an ICX standalone unit or an ICX stack to filter or rate limit specific incoming traffic. For example, you can create ACLs to perform any of the following actions:
- Rate limit DHCP packets sent to the CPU
- Permit ICMP packets
- Permit packets from a known subnet
- Deny Telnet and SSH connections
Note: On ICX 8100 and ICX 8200
devices, configuring both DSCP trust and Traffic Policy is not recommended. When
DSCP
trust and Traffic Policy are configured on the same interface, trust DSCP will
not be
honored on Layer 3 (routed) traffic, and all traffic (including packet conformance
level
0 (green conformance)) will be sent out on best effort delivery Queue 0.
Constraints on ACLs Applied to Inbound CPU Traffic
The following restrictions pertain to ACLs applied to inbound CPU traffic:
- Only fixed rate limiting is supported for CPU ACLs.
- CPU ACLs cannot be applied on any other type of interface.
- Inbound traffic on the management port is also subject to the ACL applied to the CPU.
- In a stack, an ACL can be applied to the CPU of the active controller only. This does not create issues in a stack system during a failover because the ACL is applied to all stack units when it is bound to the active controller CPU.
- The maximum number of filters in an ACL applied to the CPU is 15.
- Standard IPv4 ACLs are not supported. IPv4 extended ACLs or IPv6 ACLs must be used.
- MAC ACLs are not supported.
- A DROP action is the only exceed-action allowed in a traffic policy applied to the CPU.
- Without a permit ip any any statement in an IPv4 ACL or a permit ipv6 any any statement in an IPv6 ACL, the ACL cannot be bound to a CPU port.
- The deny any any statement is not supported for ACLs applied to the CPU.
- ACLs applied to the CPU do not support implicit filters, such as deny any any, characteristic of other ACLs applied on ICX devices. In other words, it is not possible to block all traffic to the CPU.
- In TCP and UDP filters, only the equal option (eq) is supported.
- Accounting, mirroring, and logging are not supported in ACLs applied to the CPU.
Unsupported Protocols and Options
The following protocols and options are not supported in IPv4 ACLs applied to the CPU:
- esp
- gre
- 802.1p-and-internal-marking
- 802.1p-priority-marking
- 802.1p-priority-matching
- dscp-marking
- dscp-matching
- internal-priority-marking
- precedence
- tos
The following protocols and options are not supported in IPv6 ACLs applied to the CPU: