Packet Match Criteria - Alcatel-Lucent 7750 SR-OS Configuration Manual

Table of Contents

Advertisement

Creating and Applying ACL Policies

Packet Match Criteria

SROS-based routers/switches support L2, L3 and L4 and above match criteria in IPv4, IPv6 and
MAC filters. Type and scale of each criteria supported depends on the platform, please see your
Alcatel-Lucent representative for further details. As few or as many match parameters can be
specified as required, but all conditions within a single filter policy entry must be met in order for
the packet to be considered a match and the specified action performed. Any match criteria will be
ignored unless explicitly defined. The process stops when the first complete match is found with
triggers execution of the action defined in the entry.
IP filter policy entry match criteria includes the following:
Page 430
src-ip/dst-ip
Match for the specified DSCP value against the Differentiated Services Code Point/Traffic
Class field of the outer IPv4/IPv6 header of the packet.
Destination IP address and mask — Destination IP address and mask values can be entered
as search criteria.
protocol — Match for the specified protocol against the Protocol field (for example, TCP,
UDP, IGMP) of the outer IPv4 header of the packet.
next-header — Match for the specified upper layer protocol (for example, TCP, UDP,
IGMPv6) against the Next Header field of the outer IPv6 header of the packet. Note: next-
header matching allows also to match on presence of some of the IPv6 extension headers.
See CLI section for details on which extension header match is supported. An option to
match either source or destination (Logical OR) using a single filter policy entry is
supported for some filter policies by using a single port command.
src-port/dst-port — When protocol (IPv4) or next-header (IPv6) specifies TCP, UDP, or
both for this entry, it matches against the Source Port Number/Destination Port Number of
the outer IPv4/IPv6 header of the packet.
Destination port/range — Entering the destination port number or port range allows the
filter to search for matching TCP or UDP values .
dscp — Match for the specified DSCP value against the Differentiated Services Code
Point/Traffic Class field of the outer IPv4/IPv6 header of the packet. See
Name to DSCP Value Table, on page
icmp-code — Match for the specified value against the Code field of the ICMP/ICMPv6
header of the packet.
icmp-type — Match for the specified value against the Type field of the ICMP/ICMPv6
header of the packet.
fragment — Enable fragmentation support in filter policy match. For IPv4, match against
MF bit or Fragment Offset field to determine whether the packet is a fragment or not. For
IPv6, match against Next Header Field for Fragment Extension Header value to determine
432.
7750 SR OS Router Configuration Guide
Table 9, DSCP

Advertisement

Table of Contents
loading

Table of Contents