Configuration Guide
Reflect-acl Configuration Guide
5 min
introduction introduction reflective acl is a state based dynamic access control technology primarily used for network security protection its core principle involves monitoring outbound sessions initiated from the internal network to automatically generate temporary reverse rules these rules permit response traffic to return while blocking unauthorized access initiated from external sources reflect acl configuration reflect acl configuration create reflect acl table create reflect acl table true 230,288 82805429864254,143 17194570135746#4283c7 unhandled content type #4283c7 unhandled content type #4283c7 unhandled content type unhandled content type unhandled content type unhandled content type #d8e5f5 unhandled content type #d8e5f5 unhandled content type l3/l3v6 matching filter l3/l3v6 matching filter true 148,514#4283c7 unhandled content type #4283c7 unhandled content type unhandled content type unhandled content type #d8e5f5 unhandled content type #d8e5f5 unhandled content type unhandled content type unhandled content type #d8e5f5 unhandled content type #d8e5f5 unhandled content type unhandled content type unhandled content type #d8e5f5 unhandled content type #d8e5f5 unhandled content type unhandled content type unhandled content type #d8e5f5 unhandled content type #d8e5f5 unhandled content type example of reflect acl configuration example of reflect acl configuration network requirements interface 1 of the router connects to internal network users, while interface 2 connects to the internet configure a reflexive acl on the outbound direction of interface 2 internal network hosts must first access servers on the internet before internet servers are permitted to access internal network hosts procedure sonic(config)# access list reflect l3 test egress sonic(config reflect l3 acl test)# rule 1 src ip 80 0 0 100 packet action permit sonic(config reflect l3 acl test)# exit sonic(config)# interface ethernet 2 sonic(config if 2)# acl test
