Access Control List (ACL) Library Enhancements

To implement ONEPolicy requires enhancements to certain existing Access Control List (ACL) conditions and actions, plus the addition of some new ones:

Supported Platforms

  • BlackDiamond X8 and BlackDiamond 8800 series switches
  • Summit X770, X670, X670-G2, X480, X460, X460-G2, X450-G2, X440, and X430 series switches
  • E4G-200 and E4G-400 cell site routers

Limitations

  • vlan-format mistakenly identifies untagged packets as tagged in the IFP stage for the following switches: Summit X480, Summit X650, BlackDiamond 8900-G96T-c, BlackDiamond 8900-10G24X-c, BlackDiamond 8900-G48T-xl, BlackDiamond 8900-G48X-xl, and BlackDiamond 8900-10G8X-xl.
  • fragments is partially supported on the BlackDiamond G48Te2 I/O modules. On this modules, this condition only matches fragmented packets and the last fragmented packet, and does not match the first fragment of the packet.
  • add-vlan-id is only available on switches with VFP stages.
  • IPFIX actions are only supported on Summit X460, X460-G2, and X480 series switches, BlackDiamond 8900-xl and -96T modules, and BlackDiamond X8-100G4X and BDX X8 xl-series modules.