ONEPolicy Captive Portal ACL Optimization

If not specified to do otherwise, ONEPolicy programs its captive portal-related rules outside of the reserved ACL rule space for ONEPolicy. This results in additional ACL slice usage. This feature allows you to specify that these rules are programmed within the already reserved ACL rule space at the expense of IPv4 rule capacity. This is useful for configurations where system ACL resource usage is constrained, especially on the ExtremeSwitching X440-G2 and X620 series switches, which have less ACL slice resources. For example, when policy is enabled and application telemetry is also enabled.

Supported Platforms

Summit X450-G2, X460-G2, X670-G2, and ExtremeSwitching X440-G2, X465, X590, X620, X690, X870 series switches.

New CLI Commands

configure policy captive-portal rule-use [reserved | unreserved]

Changed CLI Commands

Changes are underlined.

show policy captive-portal {web-redirect {redirect_index | all} | listening | rule-use}