IPv4, IPv6 and MAC ACLs
Forwarding Reference is not supported in ACL. If ACL is not created for RESTCONF, then you cannot bind an ACL on an interface.
You cannot delete an ACL, if it is bind on any interface. For this, delete the ACL binding and then delete ACL for RESTCONF.
If you want to update a filter of a particular sequence ID, first delete the filter and then add it back with modification.
Standard Named ACL is not possible.
Supported HTTP Operations for IPv4 ACL
PATCH method
To create IPv4 ACL and adding filter
URL: https://<host>/restconf/data/acl/acl-sets
{
"acl-sets": {
"acl-set": [
{
"name": "ext3",
"type": "ACL_IPV4",
"config": {
"name": "ext3",
"type": "ACL_IPV4"
},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 10,
"config": {
"sequence-id": 10
},
"ipv4": {
"config": {
"source-address": "10.0.0.0",
"destination-address": "20.0.0.0/24",
"dscp": 10,
"protocol": 6,
"internal-priority-marking": {
"internal-priority-marking" : 7
},
"dscp-marking": {
"dscp-marking" : 10
}
}
},
"transport": {
"config": {
"source-port": "0",
"destination-port": "0"
}
},
"actions": {
"config": {
"forwarding-action": "openconfig-acl:ACCEPT"
}
}
}
]
}
}
]
}
}
POST method
To create IPv4 ACL and adding filter
URL: https://<host>/restconf/data/acl/acl-sets
{
"acl-set": [
{
"name": "ext_acl1",
"type": "ACL_IPV4",
"config": {
"name": "ext_acl1",
"type": "ACL_IPV4"
},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 10,
"config": {
"sequence-id": 10
},
"ipv4": {
"config": {
"source-address": "20.0.0.0/24",
"destination-address": "30.0.0.0/24",
"dscp": 10,
"protocol": 6,
"internal-priority-marking": {
"internal-priority-marking" : 7
},
"dscp-marking": {
"dscp-marking" : 10
}
}
},
"transport": {
"config": {
"source-port": "0",
"destination-port": "0"
}
},
"actions": {
"config": {
"forwarding-action": "openconfig-acl:ACCEPT"
}
}
}
]
}
}
]
}
POST method (Binding on interface)
URL: https://<host>/restconf/data/acl
{
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/8",
"config": {
"id": "ethernet 1/1/8"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "ext3",
"type": "ACL_IPV4",
"config": {
"set-name": "ext3",
"type": "ACL_IPV4"
}
}
]
}
}
]
}
}
PATCH method (Binding on ingress and egress interface)
URL: https://<host>/restconf/data/acl
{
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/1",
"config": {
"id": "ethernet 1/1/1"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "ext_acl1",
"type": "ACL_IPV4",
"config": {
"set-name": "ext_acl1",
"type": "ACL_IPV4"
}
}
]
}
},
{
"id": "ethernet 1/1/2",
"config": {
"id": "ethernet 1/1/2"
},
"egress-acl-sets": {
"egress-acl-set": [
{
"set-name": "ext_acl1",
"type": "ACL_IPV4",
"config": {
"set-name": "ext_acl1",
"type": "ACL_IPV4"
}
}
]
}
}
]
}
}
DELETE : To delete a specific IPv4 ACL binding
URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F8/ingress-acl-sets/ingress-acl-set/ext3/ACL_IPV4
Request body: None Response body: None
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/ext3/ACL_IPV4
Request body: None Response body: None
GET method : To get or read specific IPv4 ACL configured in the system.
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/ext3/ACL_IPV4
Request body: None
Response body: {
"openconfig-acl:acl-set": [
{
"name": "ext3",
"type": "openconfig-acl:ACL_IPV4",
"config": {
"name": "ext3",
"type": "openconfig-acl:ACL_IPV4"
},
"state": {},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 10,
"config": {
"sequence-id": 10
},
"state": {
"sequence-id": 10
},
"ipv4": {
"config": {
"source-address": "0.0.0.0",
"destination-address": "0.0.0.0",
"dscp": 0,
"protocol": 6,
"icx-openconfig-acl-aug:internal-priority-marking": {
"internal-priority-marking": 7
},
"icx-openconfig-acl-aug:dscp-marking": {
"dscp-marking": 10
}
},
"state": {
}
},
"transport": {
"config": {
"source-port": "0",
"destination-port": "0"
},
"state": {
}
},
"input-interface": {
"state": {},
"interface-ref": {
"state": {}
}
},
"actions": {
"config": {
"forwarding-action": "openconfig-acl:ACCEPT"
}
}
}
]
}
}
]
}
GET method : To get or read specific ACL bound interface.
URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F5
Request Body: None
Response Body: {
"openconfig-acl:interfaces": {
"interface": [
{
"id": "ethernet 1/1/5",
"config": {
"id": "ethernet 1/1/5"
},
"state": {},
"interface-ref": {
"config": {
"interface": "ethernet 1/1/5"
},
"state": {}
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "ext3",
"type": "openconfig-acl:ACL_IPV4",
"config": {
"set-name": "ext3",
"type": "openconfig-acl:ACL_IPV4"
},
"state": {},
"acl-entries": {}
}
]
},
"egress-acl-sets": {}
}
]
}
}
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/15",
"config": {
"id": "ethernet 1/1/15"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "device-IPv4",
"type": "ACL_IPV4",
"config": {
"set-name": "device-IPv4",
"type": "ACL_IPV4"
}
}
]
}
}
]
}
}
Response Body: None
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/12",
"config": {
"id": "ethernet 1/1/12"
},
"egress-acl-sets": {
"egress-acl-set": [
{
"set-name": "device-IPv4",
"type": "ACL_IPV4",
"config": {
"set-name": "device-IPv4",
"type": "ACL_IPV4"
}
}
]
}
}
]
}
}
Response Body: NoneTo
DELETE filter by sequence
IDURL: https://<host>/restconf/data/acl/acl-sets/acl-set/<acl-name>/ACL_IPV4/acl-entries/acl-entry/10PATCH method to create standard ACL and adding filter
URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
"acl-sets": {
"acl-set": [
{
"name": "acl-name",
"type": "ACL_IPV4",
"standard":true,
"config": {
"name": "acl-name",
"type": "ACL_IPV4",
"standard":true
},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 30,
"config": {
"sequence-id": 30
},
"ipv4": {
"config": {
"source-address": "20.0.0.0/24"
}
},
"actions": {
"config": {
"forwarding-action": "openconfig-acl:ACCEPT"
}
}
}
]
}
}
]
}
}
Response Body: None
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
"interfaces": {
"interface": [
{
"id": "vlan 55",
"config": {
"id": "vlan 55"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "101",
"type": "ACL_IPV4",
"config": {
"set-name": "101",
"type": "ACL_IPV4"
}
}
]
}
}
]
}
}
Response Body: None
Supported HTTP operations for MAC ACL
To create MAC ACL and adding filters using PATCH method.
URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
"acl-sets": {
"acl-set": [
{
"name": "bj6",
"type": "ACL_L2",
"config": {
"name": "bj6",
"type": "ACL_L2"
},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 100,
"config": {
"sequence-id": 100
},
"l2": {
"config": {
"source-mac": "1111.2222.3333",
"source-mac-mask": "1111.2222.3333",
"destination-mac": "1111.2222.3333",
"destination-mac-mask": "1111.2222.3333",
"ethertype": 2048
}
},
"actions": {
"config": {
"forwarding-action": "ACCEPT"
}
}
}
]
}
}
]
}
}
Response Body: None
To create MAC ACL and adding filters using POST method.
URL: https://<host>/restconf/data/acl/acl-sets
{
"acl-set": [
{
"name": "bj7",
"type": "ACL_L2",
"config": {
"name": "bj7",
"type": "ACL_L2"
},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 100,
"config": {
"sequence-id": 100
},
"l2": {
"config": {
"source-mac": "1111.2222.3333",
"source-mac-mask": "1111.2222.3333",
"destination-mac": "1111.2222.3333",
"destination-mac-mask": "1111.2222.3333",
"ethertype": 2048
}
},
"actions": {
"config": {
"forwarding-action": "ACCEPT"
}
}
}
]
}
}
]
}
Response Body: None
PATCH method (Binding on ingress interface)
URL: https://<host>/restconf/data/acl/interfaces
{
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/19",
"config": {
"id": "ethernet 1/1/19"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "bj6",
"type": "ACL_L2",
"config": {
"set-name": "bj6",
"type": "ACL_L2"
}
}
]
}
}
]
}
}
POST method (Binding on an interface)
URL: https://<host>/restconf/data/acl
{
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/20",
"config": {
"id": "ethernet 1/1/20"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "bj6",
"type": "ACL_L2",
"config": {
"set-name": "bj6",
"type": "ACL_L2"
}
}
]
}
}
]
}
}
Response Body: None
PATCH method (Binding on a VLAN)
URL: https://<host>/restconf/data/acl/interfaces
{
"interfaces": {
"interface": [
{
"id": "vlan 100",
"config": {
"id": "vlan 100"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "bj6",
"type": "ACL_L2",
"config": {
"set-name": "bj6",
"type": "ACL_L2"
}
}
]
}
}
]
}
}
Response Body: None
To GET the configured MAC ACL "bj6".
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/bj6/ACL_L2
Request Body: None
Response Body: {
"openconfig-acl:acl-set": [
{
"name": "bj6",
"type": "openconfig-acl:ACL_L2",
"config": {
"name": "bj6",
"type": "openconfig-acl:ACL_L2"
},
"state": {},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 100,
"config": {
"sequence-id": 100
},
"state": {},
"l2": {
"config": {
"source-mac": "1111.2222.3333",
"source-mac-mask": "1111.2222.3333",
"destination-mac": "1111.2222.3333",
"destination-mac-mask": "1111.2222.3333",
"ethertype": 2048
},
"state": {}
},
"input-interface": {
"state": {},
"interface-ref": {
"state": {}
}
},
"actions": {
"config": {
"forwarding-action": "openconfig-acl:ACCEPT"
},
"state": {}
}
}
]
}
}
]
}
To GET MAC ACL binding on an interface
URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F19
Request Body: None
Response Body: {
"openconfig-acl:interface": [
{
"id": "ethernet 1/1/19",
"config": {
"id": "ethernet 1/1/19"
},
"state": {},
"interface-ref": {
"config": {
"interface": "ethernet 1/1/19"
},
"state": {}
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "bj6",
"type": "openconfig-acl:ACL_L2",
"config": {
"set-name": "bj6",
"type": "openconfig-acl:ACL_L2"
},
"state": {},
"acl-entries": {}
}
]
},
"egress-acl-sets": {}
}
]
}To
DELETE a specific MAC ACL from an
interfaceURL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F19/ingress-acl-sets/ingress-acl-set/bj6/ACL_L2To DELETE MAC ACL "bj6"
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/bj6/ACL_L2
Supported HTTP Operations for IPv6 ACL
PATCH method to create IPv6 ACL and adding filter
URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
"acl-sets": {
"acl-set": [
{
"name": "acl_ipv61",
"type": "ACL_IPV6",
"config": {
"name": "acl_ipv61",
"type": "ACL_IPV6"
},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 10,
"config": {
"sequence-id": 10
},
"ipv6": {
"config": {
"source-address": "1000::10/120",
"destination-address": "2000::10/100",
"dscp": 0,
"internal-priority-marking": {
"internal-priority-marking" : 7
},
"dscp-marking": {
"dscp-marking" : 10
}
}
},
"actions": {
"config": {
"forwarding-action": "ACCEPT"
}
}
}
]
}
}
]
}
}
Response Body: None
POST method to create IPv6 ACL and adding filter
URL: https://<host>/restconf/data/acl/acl-sets
Request Body: {
"acl-set": [
{
"name": "acl_ipv62",
"type": "ACL_IPV6",
"config": {
"name": "acl_ipv62",
"type": "ACL_IPV6"
},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 10,
"config": {
"sequence-id": 10
},
"ipv6": {
"config": {
"source-address": "1000::10/120",
"destination-address": "2000::10/64",
"dscp":10,
"internal-priority-marking": {
"internal-priority-marking" : 7
},
"dscp-marking": {
"dscp-marking" : 10
}
}
},
"actions": {
"config": {
"forwarding-action": "ACCEPT"
}
}
}
]
}
}
]
}
Response Body: None
PATCH method for binding on ingress and egress interfaceURL: https://<host>/restconf/data/acl/interfaces
Request Body: {
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/1",
"config": {
"id": "ethernet 1/1/1"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "acl_ipv61",
"type": "ACL_IPV6",
"config": {
"set-name": "acl_ipv61",
"type": "ACL_IPV6"
}
}
]
}
},
{
"id": "ethernet 1/1/7",
"config": {
"id": "ethernet 1/1/7"
},
"egress-acl-sets": {
"egress-acl-set": [
{
"set-name": "acl_ipv61",
"type": "ACL_IPV6",
"config": {
"set-name": "acl_ipv61",
"type": "ACL_IPV6"
}
}
]
}
}
]
}
}
Response Body: None
PATCH method for Ingress binding
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/7",
"config": {
"id": "ethernet 1/1/7"
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "acl_ipv62",
"type": "ACL_IPV6",
"config": {
"set-name": "acl_ipv62",
"type": "ACL_IPV6"
}
}
]
}
}
]
}
}
Response Body: None
PATCH method for egress binding
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
"interfaces": {
"interface": [
{
"id": "ethernet 1/1/12",
"config": {
"id": "ethernet 1/1/12"
},
"egress-acl-sets": {
"egress-acl-set": [
{
"set-name": "device-IPv6",
"type": "ACL_IPV6",
"config": {
"set-name": "device-IPv6",
"type": "ACL_IPV6"
}
}
]
}
}
]
}
}
Response Body: None
URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F7/ingress-acl-sets/ingress-acl-set/acl_ipv62/ACL_IPV6
To DELETE IPv6 ACL
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/acl_ipv61/ACL_IPV6
To GET specific IPv6 ACL configured in the system
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/acl_ipv61/ACL_IPV6
Request Body: None
Response Body: {
"openconfig-acl:acl-set": [
{
"name": "acl_ipv61",
"type": "openconfig-acl:ACL_IPV6",
"config": {
"name": "acl_ipv61",
"type": "openconfig-acl:ACL_IPV6"
},
"state": {},
"acl-entries": {
"acl-entry": [
{
"sequence-id": 10,
"config": {
"sequence-id": 10
},
"state": {
},
"ipv6": {
"config": {
"source-address": "1000::10/120",
"destination-address": "2000::10/100",
"dscp": 0,
"protocol": 0,
"icx-openconfig-acl-aug:internal-priority-marking": {
"internal-priority-marking": 7
},
"icx-openconfig-acl-aug:dscp-marking": {
"dscp-marking": 10
}
},
"state": {
}
},
"transport": {
"config": {
"source-port": "0",
"destination-port": "0"
},
"state": {
}
},
"input-interface": {
"state": {},
"interface-ref": {
"state": {}
}
},
"actions": {
"config": {
"forwarding-action": "openconfig-acl:ACCEPT"
}
}
}
]
}
}
]
}
To GET all ACL binding interfaces
URL: https://<host>/restconf/data/acl/interfaces/interface/ethernet 1%2F1%2F5
Request Body: None
Response Body: {
"openconfig-acl:interface": [
{
"id": "ethernet 1/1/5",
"config": {
"id": "ethernet 1/1/5"
},
"state": {},
"interface-ref": {
"config": {
"interface": "ethernet 1/1/5"
},
"state": {}
},
"ingress-acl-sets": {
"ingress-acl-set": [
{
"set-name": "ext3",
"type": "openconfig-acl:ACL_IPV4",
"config": {
"set-name": "ext3",
"type": "openconfig-acl:ACL_IPV4"
},
"state": {},
"acl-entries": {}
},
{
"set-name": "acl_ipv61",
"type": "openconfig-acl:ACL_IPV6",
"config": {
"set-name": "acl_ipv61",
"type": "openconfig-acl:ACL_IPV6"
},
"state": {},
"acl-entries": {}
}
]
},
"egress-acl-sets": {}
}
]
}
To DELETE ACL filter using sequence ID
URL: https://<host>/restconf/data/acl/acl-sets/acl-set/device-ipv6/ACL_IPV6/acl-entries/acl-entry/10PATCH method (Binding on VLAN)
URL: https://<host>/restconf/data/acl/interfaces
Request Body: {
"interfaces": {
"interface": [
{
"id": "vlan 55",
"config": {
"id": "vlan 55"
},
"egress-acl-sets": {
"egress-acl-set": [
{
"set-name": "acl-name",
"type": "ACL_IPV6",
"config": {
"set-name": "acl-name",
"type": "ACL_IPV6"
}
}
]
}
}
]
}
}
Response Body: None