User's Manual

Chapter 3 - Operation and Administration Using the CLI NPU Configuration
4Motion 171 System Manual
3.3.10 Configuring ACLs
ACLs are applied on traffic received from the NPU physical interfaces (DATA,
MGMT or CSCD ports), and destined towards the following virtual interfaces:
AUs
NPU
By default, all traffic destined towards the AUs is denied. Several default ACLs are
created automatically to allow some restricted traffic towards the NPU. These ACL
rules are applied automatically at the time of NPU startup or upon a change of IP
address of various interfaces. You can use the CLI to configure additional ACLs for
permitting or denying specific traffic destined towards the NPU or AUs.
You can create the following types of ACLs:
Standard: Allows you to filter traffic based on the source and destination IP
addresses.
Extended: Allows you to filter traffic based on the source and destination IP
addresses, source and destination ports, and protocol.
Display
Format
<IP address/mask> is directly connected
<IP address/mask> is directly connected
<IP address/mask> is directly connected
<IP address/mask> via <Next-hop IP address>
<IP address/mask> via <Next-hop IP address>
<IP address/mask> via <Next-hop IP address>
<IP address/mask> via <Next-hop IP address>
<IP address/mask> via <Next-hop IP address>
Command
Modes
Global command mode
IMPORTANT
You can use extended ACL 199 to configure QoS classification rules for classifying traffic originating
from the NPU into different flows. For details, refer “Configuring QoS Marking Rules” on
page 152
).