3
Automatic rule numbering and renumbering
The ID automatically assigned to an ACL rule takes the nearest higher multiple of the numbering step
to the current highest rule ID, starting with 0.
For example, if the step is 5, and there are five rules numbered 0, 5, 9, 10, and 12, the newly defined
rule is numbered 15. If the ACL does not contain a rule, the first rule is numbered 0.
Whenever the step changes, the rules are renumbered, starting from 0. For example, changing the
step from 5 to 2 renumbers rules 5, 10, 13, and 15 as rules 0, 2, 4, and 6.
Fragment filtering with ACLs
Traditional packet filtering matches only first fragments of packets, and allows all subsequent
non-first fragments to pass through. Attackers can fabricate non-first fragments to attack networks.
To avoid risks, the ACL feature is designed as follows:
•
Filters all fragments by default, including non-first fragments.
•
Allows for matching criteria modification for efficiency. For example, you can configure the ACL
to filter only non-first fragments.
Configuration restrictions and guidelines
When you configure ACLs, follow these restrictions and guidelines:
•
Matching packets are forwarded through slow forwarding if an ACL rule contains match criteria
or has functions enabled in addition to the following match criteria and functions:
{
Source and destination IP addresses.
{
Source and destination ports.
{
Transport layer protocol.
{
ICMP or ICMPv6 message type, message code, and message name.
{
VPN instance.
{
Logging.
{
Time range.
Slow forwarding requires packets to be sent to the control plane for forwarding entry calculation,
which affects the device forwarding performance.
•
On a border gateway in a VXLAN or EVPN network, an ACL applied to a Layer 3 Ethernet
interface or Layer 3 aggregate interface matches the packets on both the interface and its
subinterfaces. For information about VXLAN and EVPN, see
VXLAN Configuration Guide
and
EVPN Configuration Guide
.
Summary of Contents for FlexFabric 5940 Series
Page 23: ...17 Figure 3 QoS processing flow ...
Page 84: ...78 Figure 26 MPLS label structure ...
Page 91: ...85 Switch burst mode enable ...