Filter Policy Basics; Filter Policy Packet Match Criteria; Ipv4 Filter Policy Entry Match Criteria - Alcatel-Lucent 7450 Configuration Manual

Hide thumbs Also See for 7450:
Table of Contents

Advertisement

the packet does not match any of the entries, the system executes the default-action specified in
the filter policy: drop or forward.
For Layer 2, either an IPv4and MAC filter policy can be applied. For Layer 3 and network
interfaces, an IPv4 policy can be applied. For r-VPLS service, a L2 filter policy can be applied to
L2 forwarded traffic and L3 filter policy can be applied to L3 routed traffic. For dual stack
interfaces, if both IPv4 and filter policies are configured, the policy applied will be based on the
outer IP header of the packet. Note that non-IP packets are not hitting an IP filter policy, so the
default action in the IP filter policy will not apply to these packets.

Filter Policy Basics

The following subsections define main functionality supported by filter policies.

Filter Policy Packet Match Criteria

This section defines packet match criteria supported on SROS-based routers/switches for IPv4,
and MAC filters. Types of criteria supported depends on the hardware platform and filter
direction, please see your Alcatel-Lucent representative for further details.
General notes:

IPv4 Filter Policy Entry Match Criteria

The below lists IPv4 match criteria supported by SROS routers/switches. The criteria are
evaluated against outer IPv4 header and a L4 header that follows (if applicable). Support for a
given match criteria may depend on H/W and/or filter direction as per below description. It is
recommended not to configure a filter in a direction or on a H/W where a given match condition is
7450 ESS Router Configuration Guide
If multiple unique match criteria are specified in a single filter policy entry, all criteria
must be met in order for the packet to be considered a match against that filter policy entry
(logical AND).
Any match criteria not explicitly defined is ignored during match.
An ACL filter policy entry with match criteria defined but no action configured, is
considered incomplete and inactive (an entry is not downloaded to the line card). A filter
policy must have at least single entry active for the policy to be considered active.
An ACL filter entry with no match conditions defined matches all packets.
Because an ACL filter policy is an order list, entries should be configured (numbered)
from the most explicit to the least explicit.
Filter Policies
Page 439

Advertisement

Table of Contents
loading

Table of Contents