User's Manual

Chapter 3 - Operation and Administration Using the CLI NPU Configuration
4Motion 172 System Manual
You can create the following types of rules for an ACL:
Permit: Indicates that traffic matching the filter criteria is allowed to reach the
NPU or AUs.
Deny: Indicates that traffic matching the filter criteria is dropped, and not
allowed to reach the NPU or AUs.
You can configure multiple rules for each ACL; the priority for these rules is
applied with respect to the sequence in which these rules are configured. After
you configure an ACL, you can attach the ACL to either the NPU or the AUs or
both NPU and AUs.
All ACLs are either in the ACTIVE or INACTIVE state. The ACTIVE state indicates
that the ACL is attached to one or more interfaces; the INACTIVE state indicates
that the ACL is not attached to any interface.
By default, traffic towards the AUs is not restricted. This is implemented through
ACL 1 which is available by default. ACL 1 is attached to AUs, with Rule Action =
Permit, Source IP Address = Any and Destination IP Address = Any.
All the following automatically created standard default ACLs are attached to the
NPU virtual interface and include a single Permit rule:
The default Extended ACL 186 attached to the NPU virtual interface includes the
following Permit rules allowing certain traffic towards the Bearer interface:
Table 3-16: Default Standard ACLs
ACL Number Rule Action Source IP Address Destination IP Address
ACL 96 Permit Any Internal Management IP address
ACL 97 Permit Any External Management IP address
ACL 98 Permit Any Local Management IP address
Table 3-17: Rules of Default ACL 186
Rule Action Source IP
Address
Source
Port
Destination IP
Address
Destination
Port
Protocol
Permit Any Any Bearer IP address Any ICMP (1)