Parameter | Description |
---|
Name | Specify a name for the ACL rule. |
Precedence | Specify the rule precedence to control which ACL rule is applied when multiple rules match. If an incoming packet matches multiple rules, the IP ACL rule with the highest precedence (lowest numeric value) is applied to that packet. Each IP ACL rule must include a precedence value and each precedence value must be unique. |
Protocol | Specify an IP protocol type to match. Choices are 0-255, or one of the following: - any – (default) filter all protocols
- icmp – filter ICMP only
- icmpv6 – filter ICMPv6 only
- ospf – filter OSPF only
- tcp – filter TCP only
- udp – filter UDP only
These protocols are typically associated with particular logical port values. |
IP Interface Group | Select an IP interface group to specify to match a specific IP interface group. |
IP Interface | Select an IP interface to specify to match a specific IP interface. |
Mgmt IP Interface Group | Select a management interface group to match a specific management interface group. NOTE: The Mgmt IP Interface Group parameter is only available from the default address context, even if the default address context does not contain any other configurations. |
Mgmt IP Interface | Select a Management Interface to match a specific Management Interface. NOTE: The Mgmt IP Interface parameter is only available from the default address context, even if the default address context does not contain any other configurations. |
Source IP Address | Specify the source IP address to match. The default is 0.0.0.0. NOTE: If you configure a Source IP Address, then a Source Address Prefix Length must also be specified. |
Source Address Prefix Length | Specify a length for the source IP address prefix. Must be 0 - 128, the default is 0. |
Destination IP Address | Specify the destination IP address to match. The default is 0.0.0.0. NOTE: If you configure a Destination IP Address, then a Destination Address Prefix Length must also be specified. |
Destination Address Prefix Length | Specify a length for the destination IP address prefix. The value ranges from 0 to 128. The default is 0. |
Source Port | Specify a source port value. Must be 0 - 65535 or any, the default is any. |
Destination Port | Specify a destination port value. Must be 0 - 65535 or any, the default is any. |
Action | Specify the action to take when a packet matches the rule. The options are: |
Fill Rate | Specify the number of packets to add to the bucket credit balance (in packets/second). If packets are received at a rate exceeding this fill rate, they are discarded subject to the discard rate set in the IP Policing Alarm profile or in the PolicerAlarm monitoring this port. The bucket credit balance is always less than the configured bucket size regardless of the size of this increment. Must be 1 - 320000 or unlimited, the default is 50. |
Bucket Size | Specify the policing bucket size (in packets). This represents a credit balance that can be consumed before packets are discarded which allows for occasional traffic bursts. If a packet is received when the credit balance is less than the size of the packet, the packet is discarded subject to the discard rate set in the IP Policing Alarm profile or in the PolicerAlarm monitoring this port. Must be 1-255 or unlimited, the default is 50. |
State | Specify the administrative state for the ACL rule. - Enabled
- Disabled (default)
|
The following options appear when you create an ACL rule for a D-SBC SWe system. |
Dest Type IP Version | Specify the IP version type for the destination. The options are: |
Destination IP Address | Specify the destination IP address (IPV4/IPV6) to match. |
Destination Address Prefix Length | Specify a length for the destination IP address prefix. The value ranges from 0 to 128. |
Dest IP Interface Group | Select an IP interface group to specify to match a specific IP interface group for the destination host address. |
Dest IP Interface | Select an IP interface to specify to match a specific IP interface for the destination host address. |
Dest Mgmt IP Interface Group | Select a management interface group to match a specific management interface group for the destination host address. |
Dest Mgmt IP Interface | Select a management interface to match a specific management interface for the destination host address. |
Dest SIP Sig Port Zone | Select the zone name of the SIP signaling port for the destination address. |
Dest SIP Sig Port Index | Specify the index number for the SIP signaling port for the destination address. |