beautypg.com

Rule-based ip acls, Supported rule-based ip acl features – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 101

background image

Rule-Based IP ACLs

Supported Rule-Based IP ACL Features...................................................................... 101

ACL overview................................................................................................................ 103

How hardware-based ACLs work..................................................................................106

ACL configuration considerations................................................................................. 106

Configuring standard numbered ACLs..........................................................................107

Standard named ACL configuration.............................................................................. 109

Extended numbered ACL configuration........................................................................ 112

Extended named ACL configuration............................................................................. 118

Applying egress ACLs to Control (CPU) traffic............................................................. 122

Preserving user input for ACL TCP/UDP port numbers................................................ 122

ACL comment text management...................................................................................123

Applying an ACL to a virtual interface in a protocol-or subnet-based VLAN.................125

ACL logging...................................................................................................................126

Enabling strict control of ACL filtering of fragmented packets.......................................128

Enabling ACL support for switched traffic in the router image...................................... 129

Enabling ACL filtering based on VLAN membership or VE port membership...............130

ACLs to filter ARP packets............................................................................................132

Filtering on IP precedence and ToS values.................................................................. 134

QoS options for IP ACLs............................................................................................... 135

ACL-based rate limiting.................................................................................................140

ACL statistics................................................................................................................ 140

ACL accounting.............................................................................................................141

ACLs to control multicast features................................................................................ 142

Enabling and viewing hardware usage statistics for an ACL........................................ 142

Displaying ACL information...........................................................................................143

Troubleshooting ACLs...................................................................................................144

Policy-based routing (PBR)...........................................................................................144

Supported Rule-Based IP ACL Features

Lists the rule-based IP ACL features supported on FastIron devices.

The following tables list the individual BrocadeFastIron switches and Access Control List (ACL) features
they support. The feature support tables listed further provide the features supported on inbound traffic
and on outbound traffic. These features are supported in the Layer 2 and Layer 3 software images,
except where explicitly noted.

Feature

ICX 6430

ICX 6450

FCX

ICX 6610

ICX 6650

FSX 800
FSX 1600

ICX 7750

Supported ACL features on inbound
traffic

FastIron Ethernet Switch Security Configuration Guide

101

53-1003088-03