Network-Port Vprn Filter Policy; Isid Mac Filters - Alcatel-Lucent 7450 Configuration Manual

Hide thumbs Also See for 7450:
Table of Contents

Advertisement

Network-port VPRN Filter Policy

Network-port L3 service-aware filter feature allows operators to deploy VPRN service aware
ingress filtering on network ports. A single ingress filter of scope template can each be defined for
IPv4 against a VPRN service. The filter applies to all unicast traffic arriving on auto-bind and
explicit-spoke network interfaces for that service. The network interface can be either Inter-AS, or
Intra-AS. The filter does not apply to traffic arriving on access interfaces (SAP, spoke-sdp,
network-ingress (CsC), rVPLS, eVPN).
The same filter can be used on access interfaces of the given VPRN, can embed other filters
(including OpenFlow), can be chained to a system filter, and can be used by other L2 or L3
services.
The filter is deployed on all line cards (chassis network mode D is required). There are no
limitations related to filter match/action criteria or embedding. The filter is programmed on line
cards against ILM entries for this service. All label-types are supported. If an ILM entry has a filter
index programmed, that filter is used when the ILM is used in packet forwarding; otherwise, no
filter is used on the service traffic.
Caveats:

ISID MAC Filters

ISID filters are a type of MAC filters that allows filtering based on the ISID values rather than L2
criteria used by MAC filters of type "normal" or "vid". ISID filters can be deployed on iVPLS
PBB SAPs and ePipe PBB SAPs in the following scenarios:
The MMRP usage of the mrp-policy ensures automatically that traffic using Group BMAC is not
flooded between domains. However; there could be a small transitory periods when traffic
originated from PBB BEB with unicast BMAC destination may be flooded in the BVPLS context
as unknown unicast in the BVPLS context for both IVPLS and PBB Epipe. To restrict distribution
of this traffic for local PBB services ISID filters can be deployed. The mac-filter configured with
7450 ESS Router Configuration Guide
ip-filter 10 create
chain-to-system-filter
filter-name "test-name"
embed-filter open-flow "test" offset 100
exit
exit
Network port L3 service-aware filters do not support flowspec and LI (cannot use filter
inside LI infrastructure nor have LI sources within the VPRN filter).
Filter Policies
Page 453

Advertisement

Table of Contents
loading

Table of Contents