ACL-Netconf
此内容尚不支持你的语言。
Resources Summary
Section titled “Resources Summary”| YANG Path | get/get-config | edit-config | rpc |
|---|---|---|---|
| /access-list-nexthop-groups/{id} | Y | merge, replace, create, delete | — |
| /access-list-nexthop-groups/{id}/nexthop/{ip-address}/{vrf-name} | Y | replace, create, delete | — |
| /access-lists/{name} | Y | merge, replace, create, delete | — |
| /access-lists/{name}/access-list-entries/{ruleid} | Y | merge, replace, create, delete | — |
| /clear-counters-acl | — | — | Y |
| /show-counters-acl | — | — | Y |
Examples
Section titled “Examples”This chapter provides examples on how to use Netconf to manage ACL configurations on AsterNOS devices.
Create ACL Table with Rules And Bind to Interface
Section titled “Create ACL Table with Rules And Bind to Interface”Request example to create acl via edit-config.
<config><top> <access-lists> <access-list operation="create"> <name>l3in</name> <type>L3</type> <stage>ingress</stage> <description>l3in</description> <bind-intfs>Ethernet1</bind-intfs> <bind-intfs>Ethernet2</bind-intfs> <access-list-entries> <access-list-entry> <ruleid>10</ruleid> <actions> <packet-action>FORWARD</packet-action> </actions> <matches> <ethernet-type>0x800</ethernet-type> <source-ip>12.1.2.3</source-ip> <destination-ip>13.1.3.2</destination-ip> <ip-type>IPV4ANY</ip-type> </matches> </access-list-entry> <access-list-entry> <ruleid>11</ruleid> <actions> <packet-action>TRAP</packet-action> </actions> <matches> <outer-vlan>100</outer-vlan> <vlan-pri>1</vlan-pri> <ip-protocol>17</ip-protocol> <source-port>31020</source-port> <destination-port>21030</destination-port> </matches> </access-list-entry> </access-list-entries> </access-list> </access-lists></top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74"> <ok/></rpc-reply>Create ACL Rule Entries
Section titled “Create ACL Rule Entries”Request example to create acl via edit-config.
<config><top> <access-lists> <access-list> <name>l3in</name> <access-list-entries operation="create"> <access-list-entry> <ruleid>100</ruleid> <actions> <packet-action>FORWARD</packet-action> </actions> <matches> <ethernet-type>0x800</ethernet-type> <source-ip>120.10.20.40</source-ip> <destination-ip>13.10.30.20</destination-ip> <ip-type>IPV4ANY</ip-type> </matches> </access-list-entry> </access-list-entries> </access-list> </access-lists></top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74"> <ok/></rpc-reply>Merge ACL Rule Entry
Section titled “Merge ACL Rule Entry”Request example to merge acl rule via edit-config.
<config> <top> <access-lists> <access-list> <name>abc</name> <type>L3</type> <stage>ingress</stage> <access-list-entries> <access-list-entry operation="merge"> <ruleid>100</ruleid> <actions> <packet-action>FORWARD</packet-action> </actions> <matches> <destination-ip>10.0.0.1/24</destination-ip> </matches> </access-list-entry> </access-list-entries> </access-list> </access-lists> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74"> <ok/></rpc-reply>Delete ACL Rule Entry
Section titled “Delete ACL Rule Entry”Request example to delete acl via edit-config.
<config><top> <access-lists> <access-list> <name>l3in</name> <access-list-entries> <access-list-entry operation="delete"> <ruleid>10</ruleid> </access-list-entry> </access-list-entries> </access-list> </access-lists></top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74"> <ok/></rpc-reply>Delete ACL Table
Section titled “Delete ACL Table”Request example to delete acl via edit-config.
<config><top> <access-lists> <access-list operation="delete"> <name>l3in</name> </access-list> </access-lists></top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74"> <ok/></rpc-reply>Get ACL Table
Section titled “Get ACL Table”Request example to get acl via get-config.
<filter type="subtree"> <top> <access-lists> <access-list> <name>l3in</name> </access-list> </access-lists> </top></filter>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:8948502b-d510-4013-a34a-854febf01b0b"> <data> <top> <access-lists xmlns="http://asterfusion.com/ns/yang/asternos-acl"> <access-list> <name>l3in</name> <type>L3</type> <stage>ingress</stage> <description>l3in</description> <bind-intfs>Ethernet1</bind-intfs> <bind-intfs>Ethernet2</bind-intfs> <access-list-entries> <access-list-entry> <ruleid>10</ruleid> <actions> <packet-action>FORWARD</packet-action> </actions> <matches> <ethernet-type>0x800</ethernet-type> <ip-type>IPV4ANY</ip-type> <source-ip>12.1.2.3</source-ip> <destination-ip>13.1.3.2</destination-ip> </matches> </access-list-entry> <access-list-entry> <ruleid>11</ruleid> <actions> <packet-action>TRAP</packet-action> </actions> <matches> <outer-vlan>100</outer-vlan> <ip-protocol>17</ip-protocol> <source-port>31020</source-port> <destination-port>21030</destination-port> <vlan-pri>1</vlan-pri> </matches> </access-list-entry> </access-list-entries> </access-list> </access-lists> </top> </data></rpc-reply>Show ACL Counters
Section titled “Show ACL Counters”Request example to show acl counters via rpc show-counters-acl.
<rpc> <show-counters-acl> <table-name>l3in</table-name> </show-counters-acl></rpc>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:ad92a25d-8612-411e-9d82-a9c9572c6563"> <data xmlns="http://asterfusion.com/ns/yang/asternos-acl"> RULE NAME TABLE NAME PRIO PACKETS COUNT BYTES COUNT ----------- ------------ ------ --------------- ------------- 11 l3in 1011 0 0 10 l3in 1010 0 0 </data></rpc-reply>Clear ACL Counters
Section titled “Clear ACL Counters”Request example to clear acl counters via rpc clear-counters-acl.
<rpc> <clear-counters-acl/></rpc>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74"> <ok/></rpc-reply>Properties Descriptions
Section titled “Properties Descriptions”Access List Nexthop Groups
Section titled “Access List Nexthop Groups”Tree Diagram
module: asternos-acl +--rw access-list-nexthop-groups +--rw access-list-nexthop-group* [id] +--rw id uint8 +--rw nexthop* [ip-address vrf-name] | +--rw ip-address inet:ip-address-no-zone | +--rw vrf-name vrf:vrf-ref | +--rw interface-name? union +--rw commit? booleanTable of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| access-list-nexthop-groups | M | Path-only node, has no configurable value. | |
| access-list-nexthop-group | M | Path-only node, has no configurable value. | |
| id | O | 1..12 | |
| nexthop | M | Path-only node, has no configurable value. | |
| ip-address | O | inet:ip-address-no-zone | Nexthop ip address with no zone. |
| vrf-name | O | vrf:vrf-ref | |
| interface-name | O | Ethernet name | The name of the interface. |
| commit | O | ”true" "false” | This is a special leaf to control behavior of server on processing running configuration. If set to false, configurations within its ancestor setting to running datastore WOULD NOT be transferred to operational datastore automatically, until a request containing this leaf with value ‘true’ comes. Normally this leaf can be ignored. Default value: True |
Nexthop
Section titled “Nexthop”Tree Diagram
module: asternos-acl +--rw access-list-nexthop-groupsAccess Lists
Section titled “Access Lists”Tree Diagram
module: asternos-acl +--rw access-lists +--rw access-list* [name] +--rw name string +--rw type identityref +--rw stage? acl-stage +--rw services* identityref +--rw description? string +--rw bind-intfs* if:interface-ref +--rw access-list-entries +--rw access-list-entry* [ruleid] +--rw ruleid uint16 +--rw actions | +--rw packet-action? identityref | +--rw ingress-mirror-session? uint8 | +--rw egress-mirror-session? uint8 | +--rw set-dscp? uint8 | +--rw ingress-sample-rate? uint32 | +--rw egress-sample-rate? uint32 | +--rw traffic-behavior? string | +--rw redirect-action? redirect-destination | +--rw redirect-action-ip-params? union +--rw matches +--rw ethernet-type? string +--rw outer-vlan? string +--rw ip-type? acl-ip-type +--rw ip-protocol? uint8 +--rw source-ip? union +--rw destination-ip? union +--rw source-ipv6? union +--rw destination-ipv6? union +--rw icmp-type? uint8 +--rw icmpv6-type? uint8 +--rw source-port? inet:port-number +--rw destination-port? inet:port-number +--rw vlan-pri? uint8 +--rw source-mac? yang:mac-address +--rw dscp? uint8Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| access-lists | M | Path-only node, has no configurable value. | |
| access-list | M | Path-only node, has no configurable value. | |
| name | O | string (length 1..64) | |
| type | M | ”L3V6" "L3" "CTRLPLANEV6" "CTRLPLANE” | |
| stage | O | ”ingress" "egress” | |
| services | O | ”SNMP" "NTP" "TELNET" "SSH” | Only supported on tables where type is ctrlplane. |
| description | O | string | |
| bind-intfs | O | if:interface-ref | The acl rule can be bound to either the aggregation port or the Ethernet port to take effect. |
| access-list-entries | M | Path-only node, has no configurable value. | |
| access-list-entry | M | Path-only node, has no configurable value. | |
| ruleid | O | 0..2999 | |
| actions | M | Path-only node, has no configurable value. | |
| packet-action | O | ”TRAP" "FORWARD" "COPY" "DROP” | Specifies the packet action to be taken as part of the ACL rule. This action determines how packets are forwarded, dropped, or processed further. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress, CTRLPLANE/CTRLPLANEV6 ingress |
| ingress-mirror-session | O | 1..7 | Configures an ingress mirror session identifier (1-7) for mirroring incoming traffic. This action allows duplicating traffic to a monitoring or analysis port. Applicable to ACL tables: Mirror/Mirrorv6 ingress |
| egress-mirror-session | O | 1..7 | Configures an egress mirror session identifier (1-7) for mirroring outgoing traffic. Facilitates traffic analysis by directing a copy of traffic to a designated port. Applicable to ACL tables: Mirror/Mirrorv6 egress |
| set-dscp | O | 0..63 | Sets the DSCP. Applicable to ACL tables: Layer 3 IPv4/IPv6 egress |
| ingress-sample-rate | O | 8000..1000000 | Sets the sample rate for ingress traffic. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress |
| egress-sample-rate | O | 8000..1000000 | Sets the sample rate for egress traffic. Applicable to ACL tables: Layer 3 IPv4/IPv6 egress |
| traffic-behavior | O | string | Configuring Interface Speed Limiting Policies. Applicable to ACL tables: Layer 2 ingress, Layer 3 IPv4/IPv6 ingress, Mirror/Mirrorv6 ingress, Flowctrl ingress |
| redirect-action | O | Ethernet name 1..12 An IPv4 address without a zone index. This type, derived from the type ipv4-address, may be used in situations where the zone is known from the context and no zone index is needed. An IPv6 address without a zone index. This type, derived from the type ipv6-address, may be used in situations where the zone is known from the context and no zone index is needed. | Defines the redirection destination for matched packets. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress. |
| redirect-action-ip-params | O | Ethernet name → asternos-vrf:vrf-ref | Defines the redirection destination interface or vrf with ipv4/ipv6 address for matched packets. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress and redirect-action is IPv4/IPv6 address. |
| matches | M | Path-only node, has no configurable value. | |
| ethernet-type | O | None | Matches the Ethernet frame type to be matched in the ACL rule. It accepts hexadecimal values ranging from 0x0000 to 0xffff, aiding in distinguishing different L2 protocols. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress |
| outer-vlan | O | None | Matches the outer VLAN tag in a tagged frame, supporting a wide range of VLAN IDs (from 1 to 4094) with optional EtherType (in hexadecimal format) following a slash (/) for further refinement. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress |
| ip-type | O | ”NON-IP" "IPV4ANY" "IPV6ANY" "ARP” | Matches the IP type(NON-IP/IPV4ANY/IPV6ANY/ARP) to be inspected by the ACL. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress |
| ip-protocol | O | 0..255 | Matches the protocol field in the IP header, accepting values between 0 and 255 to filter traffic based on the upper-layer protocol used. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress |
| source-ip | O | A.B.C.D/M The ipv4-address type represents an IPv4 address in dotted-quad notation. The IPv4 address may include a zone index, separated by a % sign. If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document. The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used. The canonical format for the zone index is the numerical format | Matches the source IPv4 address to filter network traffic based on its origin. Applicable to ACL tables: Layer 3 IPv4 ingress/egress, CTRLPLANE ingress |
| destination-ip | O | A.B.C.D/M The ipv4-address type represents an IPv4 address in dotted-quad notation. The IPv4 address may include a zone index, separated by a % sign. If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document. The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used. The canonical format for the zone index is the numerical format | Matches the destination IPv4 address to filter network traffic based on its intended endpoint. Applicable to ACL tables: Layer 3 IPv4 ingress/egress, CTRLPLANE ingress |
| source-ipv6 | O | The ipv6-prefix type represents an IPv6 prefix. The prefix length is given by the number following the slash character and must be less than or equal to 128. A prefix length value of n corresponds to an IP address mask that has n contiguous 1-bits from the most significant bit (MSB) and all other bits set to 0. The canonical format of an IPv6 prefix has all bits of the IPv6 address set to zero that are not part of the IPv6 prefix. Furthermore, the IPv6 address is represented as defined in Section 4 of RFC 5952. The definition of ipv6-prefix does not require that bits, which are not part of the prefix, are set to zero. However, implementations have to return values in canonical format, which requires non-prefix bits to be set to zero. This means that 2001:db8::1/64 must be accepted as a valid value but it will be converted into the canonical format 2001:db8::/64. The ipv6-address type represents an IPv6 address in full, mixed, shortened, and shortened-mixed notation. The IPv6 address may include a zone index, separated by a % sign. If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document. The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used. The canonical format of IPv6 addresses uses the textual representation defined in Section 4 of RFC 5952. The canonical format for the zone index is the numerical format as described in Section 11.2 of RFC 4007. | Matches the source IPv6 address to filter network traffic based on its origin. Applicable to ACL tables: Layer 3 IPv6 ingress/egress, CTRLPLANEV6 ingress |
| destination-ipv6 | O | The ipv6-prefix type represents an IPv6 prefix. The prefix length is given by the number following the slash character and must be less than or equal to 128. A prefix length value of n corresponds to an IP address mask that has n contiguous 1-bits from the most significant bit (MSB) and all other bits set to 0. The canonical format of an IPv6 prefix has all bits of the IPv6 address set to zero that are not part of the IPv6 prefix. Furthermore, the IPv6 address is represented as defined in Section 4 of RFC 5952. The definition of ipv6-prefix does not require that bits, which are not part of the prefix, are set to zero. However, implementations have to return values in canonical format, which requires non-prefix bits to be set to zero. This means that 2001:db8::1/64 must be accepted as a valid value but it will be converted into the canonical format 2001:db8::/64. The ipv6-address type represents an IPv6 address in full, mixed, shortened, and shortened-mixed notation. The IPv6 address may include a zone index, separated by a % sign. If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document. The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used. The canonical format of IPv6 addresses uses the textual representation defined in Section 4 of RFC 5952. The canonical format for the zone index is the numerical format as described in Section 11.2 of RFC 4007. | Matches the destination IPv6 address to filter network traffic based on its intended endpoint. Applicable to ACL tables: Layer 3 IPv6 ingress/egress, CTRLPLANEV6 ingress |
| icmp-type | O | 0..16 | Matches the ICMP traffic based on the message type. Applicable to ACL tables: Layer 3 IPv4 ingress/egress |
| icmpv6-type | O | 1..137 | Matches the ICMPv6 traffic based on the message type. Applicable to ACL tables: Layer 3 IPv6 ingress |
| source-port | O | inet:port-number | Matches the source transport layer port numbers. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress |
| destination-port | O | inet:port-number | Matches the destination transport layer port numbers. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress |
| vlan-pri | O | 0..7 | Matches the the 3-bit VLAN Priority Code Point. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress |
| source-mac | O | yang:mac-address | Matches the source mac-address. Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress |
| dscp | O | 0..63 | Matches the Differentiated Services Code Point in the IP header, allowing Quality of Service (QoS) differentiation with a range of 0 to 63. Applicable to ACL tables: Layer 3 IPv4 or IPv6 ingress/egress |
Access List Entry
Section titled “Access List Entry”Tree Diagram
module: asternos-acl +--rw access-listsClear Counters Acl
Section titled “Clear Counters Acl”Tree Diagram
module: asternos-acl
rpcs: +---x clear-counters-aclTable of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| clear-counters-acl | O |
Show Counters Acl
Section titled “Show Counters Acl”Tree Diagram
module: asternos-acl
rpcs: +---x show-counters-acl +---w input | +---w table-name* string | +---w rule-id* string +--ro output +--ro data? <anydata>Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| show-counters-acl | O | ||
| table-name | O | string | ACL table name. |
| rule-id | O | string | ACL rule ID. |
| data | O | The rule counters for the specified parameter according to the value of input(table name, rule id). |