跳转到内容
Ask AI

ACL-Netconf

此内容尚不支持你的语言。

YANG Pathget/get-configedit-configrpc
/access-list-nexthop-groups/{id}Ymerge, replace, create, delete—
/access-list-nexthop-groups/{id}/nexthop/{ip-address}/{vrf-name}Yreplace, create, delete—
/access-lists/{name}Ymerge, replace, create, delete—
/access-lists/{name}/access-list-entries/{ruleid}Ymerge, replace, create, delete—
/clear-counters-acl——Y
/show-counters-acl——Y

This chapter provides examples on how to use Netconf to manage ACL configurations on AsterNOS devices.

Create ACL Table with Rules And Bind to Interface

Section titled “Create ACL Table with Rules And Bind to Interface”

Request example to create acl via edit-config.

<config><top>
<access-lists>
<access-list operation="create">
<name>l3in</name>
<type>L3</type>
<stage>ingress</stage>
<description>l3in</description>
<bind-intfs>Ethernet1</bind-intfs>
<bind-intfs>Ethernet2</bind-intfs>
<access-list-entries>
<access-list-entry>
<ruleid>10</ruleid>
<actions>
<packet-action>FORWARD</packet-action>
</actions>
<matches>
<ethernet-type>0x800</ethernet-type>
<source-ip>12.1.2.3</source-ip>
<destination-ip>13.1.3.2</destination-ip>
<ip-type>IPV4ANY</ip-type>
</matches>
</access-list-entry>
<access-list-entry>
<ruleid>11</ruleid>
<actions>
<packet-action>TRAP</packet-action>
</actions>
<matches>
<outer-vlan>100</outer-vlan>
<vlan-pri>1</vlan-pri>
<ip-protocol>17</ip-protocol>
<source-port>31020</source-port>
<destination-port>21030</destination-port>
</matches>
</access-list-entry>
</access-list-entries>
</access-list>
</access-lists>
</top></config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74">
<ok/>
</rpc-reply>

Request example to create acl via edit-config.

<config><top>
<access-lists>
<access-list>
<name>l3in</name>
<access-list-entries operation="create">
<access-list-entry>
<ruleid>100</ruleid>
<actions>
<packet-action>FORWARD</packet-action>
</actions>
<matches>
<ethernet-type>0x800</ethernet-type>
<source-ip>120.10.20.40</source-ip>
<destination-ip>13.10.30.20</destination-ip>
<ip-type>IPV4ANY</ip-type>
</matches>
</access-list-entry>
</access-list-entries>
</access-list>
</access-lists>
</top></config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74">
<ok/>
</rpc-reply>

Request example to merge acl rule via edit-config.

<config>
<top>
<access-lists>
<access-list>
<name>abc</name>
<type>L3</type>
<stage>ingress</stage>
<access-list-entries>
<access-list-entry operation="merge">
<ruleid>100</ruleid>
<actions>
<packet-action>FORWARD</packet-action>
</actions>
<matches>
<destination-ip>10.0.0.1/24</destination-ip>
</matches>
</access-list-entry>
</access-list-entries>
</access-list>
</access-lists>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74">
<ok/>
</rpc-reply>

Request example to delete acl via edit-config.

<config><top>
<access-lists>
<access-list>
<name>l3in</name>
<access-list-entries>
<access-list-entry operation="delete">
<ruleid>10</ruleid>
</access-list-entry>
</access-list-entries>
</access-list>
</access-lists>
</top></config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74">
<ok/>
</rpc-reply>

Request example to delete acl via edit-config.

<config><top>
<access-lists>
<access-list operation="delete">
<name>l3in</name>
</access-list>
</access-lists>
</top></config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74">
<ok/>
</rpc-reply>

Request example to get acl via get-config.

<filter type="subtree">
<top>
<access-lists>
<access-list>
<name>l3in</name>
</access-list>
</access-lists>
</top>
</filter>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:8948502b-d510-4013-a34a-854febf01b0b">
<data>
<top>
<access-lists xmlns="http://asterfusion.com/ns/yang/asternos-acl">
<access-list>
<name>l3in</name>
<type>L3</type>
<stage>ingress</stage>
<description>l3in</description>
<bind-intfs>Ethernet1</bind-intfs>
<bind-intfs>Ethernet2</bind-intfs>
<access-list-entries>
<access-list-entry>
<ruleid>10</ruleid>
<actions>
<packet-action>FORWARD</packet-action>
</actions>
<matches>
<ethernet-type>0x800</ethernet-type>
<ip-type>IPV4ANY</ip-type>
<source-ip>12.1.2.3</source-ip>
<destination-ip>13.1.3.2</destination-ip>
</matches>
</access-list-entry>
<access-list-entry>
<ruleid>11</ruleid>
<actions>
<packet-action>TRAP</packet-action>
</actions>
<matches>
<outer-vlan>100</outer-vlan>
<ip-protocol>17</ip-protocol>
<source-port>31020</source-port>
<destination-port>21030</destination-port>
<vlan-pri>1</vlan-pri>
</matches>
</access-list-entry>
</access-list-entries>
</access-list>
</access-lists>
</top>
</data>
</rpc-reply>

Request example to show acl counters via rpc show-counters-acl.

<rpc>
<show-counters-acl>
<table-name>l3in</table-name>
</show-counters-acl>
</rpc>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:ad92a25d-8612-411e-9d82-a9c9572c6563">
<data xmlns="http://asterfusion.com/ns/yang/asternos-acl">
RULE NAME TABLE NAME PRIO PACKETS COUNT BYTES COUNT
----------- ------------ ------ --------------- -------------
11 l3in 1011 0 0
10 l3in 1010 0 0
</data>
</rpc-reply>

Request example to clear acl counters via rpc clear-counters-acl.

<rpc>
<clear-counters-acl/>
</rpc>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:f20f182e-f568-49d0-ad82-aaac24244f74">
<ok/>
</rpc-reply>

Tree Diagram

module: asternos-acl
+--rw access-list-nexthop-groups
+--rw access-list-nexthop-group* [id]
+--rw id uint8
+--rw nexthop* [ip-address vrf-name]
| +--rw ip-address inet:ip-address-no-zone
| +--rw vrf-name vrf:vrf-ref
| +--rw interface-name? union
+--rw commit? boolean

Table of Properties

NameRequiredType/RangeDescription
access-list-nexthop-groupsMPath-only node, has no configurable value.
access-list-nexthop-groupMPath-only node, has no configurable value.
idO1..12
nexthopMPath-only node, has no configurable value.
ip-addressOinet:ip-address-no-zoneNexthop ip address with no zone.
vrf-nameOvrf:vrf-ref
interface-nameOEthernet nameThe name of the interface.
commitO”true"
"false”
This is a special leaf to control behavior of server on processing running configuration.

If set to false, configurations within its ancestor setting to running datastore WOULD NOT be transferred to operational datastore automatically, until a request containing this leaf with value ‘true’ comes. Normally this leaf can be ignored.
Default value: True

Tree Diagram

module: asternos-acl
+--rw access-list-nexthop-groups

Tree Diagram

module: asternos-acl
+--rw access-lists
+--rw access-list* [name]
+--rw name string
+--rw type identityref
+--rw stage? acl-stage
+--rw services* identityref
+--rw description? string
+--rw bind-intfs* if:interface-ref
+--rw access-list-entries
+--rw access-list-entry* [ruleid]
+--rw ruleid uint16
+--rw actions
| +--rw packet-action? identityref
| +--rw ingress-mirror-session? uint8
| +--rw egress-mirror-session? uint8
| +--rw set-dscp? uint8
| +--rw ingress-sample-rate? uint32
| +--rw egress-sample-rate? uint32
| +--rw traffic-behavior? string
| +--rw redirect-action? redirect-destination
| +--rw redirect-action-ip-params? union
+--rw matches
+--rw ethernet-type? string
+--rw outer-vlan? string
+--rw ip-type? acl-ip-type
+--rw ip-protocol? uint8
+--rw source-ip? union
+--rw destination-ip? union
+--rw source-ipv6? union
+--rw destination-ipv6? union
+--rw icmp-type? uint8
+--rw icmpv6-type? uint8
+--rw source-port? inet:port-number
+--rw destination-port? inet:port-number
+--rw vlan-pri? uint8
+--rw source-mac? yang:mac-address
+--rw dscp? uint8

Table of Properties

NameRequiredType/RangeDescription
access-listsMPath-only node, has no configurable value.
access-listMPath-only node, has no configurable value.
nameOstring (length 1..64)
typeM”L3V6"
"L3"
"CTRLPLANEV6"
"CTRLPLANE”
stageO”ingress"
"egress”
servicesO”SNMP"
"NTP"
"TELNET"
"SSH”
Only supported on tables where type is ctrlplane.
descriptionOstring
bind-intfsOif:interface-refThe acl rule can be bound to either the aggregation port or the Ethernet port to take effect.
access-list-entriesMPath-only node, has no configurable value.
access-list-entryMPath-only node, has no configurable value.
ruleidO0..2999
actionsMPath-only node, has no configurable value.
packet-actionO”TRAP"
"FORWARD"
"COPY"
"DROP”
Specifies the packet action to be taken as part of the ACL rule.

This action determines how packets are forwarded, dropped, or processed further.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress,

CTRLPLANE/CTRLPLANEV6 ingress
ingress-mirror-sessionO1..7Configures an ingress mirror session identifier (1-7) for mirroring incoming traffic.

This action allows duplicating traffic to a monitoring or analysis port.

Applicable to ACL tables: Mirror/Mirrorv6 ingress
egress-mirror-sessionO1..7Configures an egress mirror session identifier (1-7) for mirroring outgoing traffic.

Facilitates traffic analysis by directing a copy of traffic to a designated port.

Applicable to ACL tables: Mirror/Mirrorv6 egress
set-dscpO0..63Sets the DSCP.

Applicable to ACL tables: Layer 3 IPv4/IPv6 egress
ingress-sample-rateO8000..1000000Sets the sample rate for ingress traffic.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress
egress-sample-rateO8000..1000000Sets the sample rate for egress traffic.

Applicable to ACL tables: Layer 3 IPv4/IPv6 egress
traffic-behaviorOstringConfiguring Interface Speed Limiting Policies.

Applicable to ACL tables: Layer 2 ingress, Layer 3 IPv4/IPv6 ingress, Mirror/Mirrorv6 ingress, Flowctrl ingress
redirect-actionOEthernet name
1..12
An IPv4 address without a zone index. This type, derived from the type ipv4-address, may be used in situations where the zone is known from the context and no zone index is needed.
An IPv6 address without a zone index. This type, derived from the type ipv6-address, may be used in situations where the zone is known from the context and no zone index is needed.
Defines the redirection destination for matched packets.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress.
redirect-action-ip-paramsOEthernet name
→ asternos-vrf:vrf-ref
Defines the redirection destination interface or vrf with ipv4/ipv6 address for matched packets.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress and redirect-action is IPv4/IPv6 address.
matchesMPath-only node, has no configurable value.
ethernet-typeONoneMatches the Ethernet frame type to be matched in the ACL rule.

It accepts hexadecimal values ranging from 0x0000 to 0xffff, aiding in distinguishing different L2 protocols.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress
outer-vlanONoneMatches the outer VLAN tag in a tagged frame, supporting a wide range of VLAN IDs (from 1 to 4094) with optional EtherType (in hexadecimal format) following a slash (/) for further refinement.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress
ip-typeO”NON-IP"
"IPV4ANY"
"IPV6ANY"
"ARP”
Matches the IP type(NON-IP/IPV4ANY/IPV6ANY/ARP) to be inspected by the ACL.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress
ip-protocolO0..255Matches the protocol field in the IP header, accepting values between 0 and 255 to filter traffic based on the upper-layer protocol used.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress
source-ipOA.B.C.D/M
The ipv4-address type represents an IPv4 address in dotted-quad notation. The IPv4 address may include a zone index, separated by a % sign. If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document.

The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used.

The canonical format for the zone index is the numerical format
Matches the source IPv4 address to filter network traffic based on its origin.

Applicable to ACL tables: Layer 3 IPv4 ingress/egress, CTRLPLANE ingress
destination-ipOA.B.C.D/M
The ipv4-address type represents an IPv4 address in dotted-quad notation. The IPv4 address may include a zone index, separated by a % sign. If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document.

The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used.

The canonical format for the zone index is the numerical format
Matches the destination IPv4 address to filter network traffic based on its intended endpoint.

Applicable to ACL tables: Layer 3 IPv4 ingress/egress, CTRLPLANE ingress
source-ipv6OThe ipv6-prefix type represents an IPv6 prefix.

The prefix length is given by the number following the slash character and must be less than or equal to 128.

A prefix length value of n corresponds to an IP address mask that has n contiguous 1-bits from the most significant bit (MSB) and all other bits set to 0.

The canonical format of an IPv6 prefix has all bits of the IPv6 address set to zero that are not part of the IPv6 prefix. Furthermore, the IPv6 address is represented as defined in Section 4 of RFC 5952.

The definition of ipv6-prefix does not require that bits, which are not part of the prefix, are set to zero. However, implementations have to return values in canonical format, which requires non-prefix bits to be set to zero. This means that 2001:db8::1/64 must be accepted as a valid value but it will be converted into the canonical format 2001:db8::/64.
The ipv6-address type represents an IPv6 address in full, mixed, shortened, and shortened-mixed notation. The IPv6 address may include a zone index, separated by a % sign.

If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document.

The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used.

The canonical format of IPv6 addresses uses the textual representation defined in Section 4 of RFC 5952. The canonical format for the zone index is the numerical format as described in Section 11.2 of RFC 4007.
Matches the source IPv6 address to filter network traffic based on its origin.

Applicable to ACL tables: Layer 3 IPv6 ingress/egress, CTRLPLANEV6 ingress
destination-ipv6OThe ipv6-prefix type represents an IPv6 prefix.

The prefix length is given by the number following the slash character and must be less than or equal to 128.

A prefix length value of n corresponds to an IP address mask that has n contiguous 1-bits from the most significant bit (MSB) and all other bits set to 0.

The canonical format of an IPv6 prefix has all bits of the IPv6 address set to zero that are not part of the IPv6 prefix. Furthermore, the IPv6 address is represented as defined in Section 4 of RFC 5952.

The definition of ipv6-prefix does not require that bits, which are not part of the prefix, are set to zero. However, implementations have to return values in canonical format, which requires non-prefix bits to be set to zero. This means that 2001:db8::1/64 must be accepted as a valid value but it will be converted into the canonical format 2001:db8::/64.
The ipv6-address type represents an IPv6 address in full, mixed, shortened, and shortened-mixed notation. The IPv6 address may include a zone index, separated by a % sign.

If a system uses zone names that are not represented in UTF-8, then an implementation needs to use some mechanism to transform the local name into UTF-8. The definition of such a mechanism is outside the scope of this document.

The zone index is used to disambiguate identical address values. For link-local addresses, the zone index will typically be the interface index number or the name of an interface. If the zone index is not present, the default zone of the device will be used.

The canonical format of IPv6 addresses uses the textual representation defined in Section 4 of RFC 5952. The canonical format for the zone index is the numerical format as described in Section 11.2 of RFC 4007.
Matches the destination IPv6 address to filter network traffic based on its intended endpoint.

Applicable to ACL tables: Layer 3 IPv6 ingress/egress, CTRLPLANEV6 ingress
icmp-typeO0..16Matches the ICMP traffic based on the message type.

Applicable to ACL tables: Layer 3 IPv4 ingress/egress
icmpv6-typeO1..137Matches the ICMPv6 traffic based on the message type.

Applicable to ACL tables: Layer 3 IPv6 ingress
source-portOinet:port-numberMatches the source transport layer port numbers.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress
destination-portOinet:port-numberMatches the destination transport layer port numbers.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress
vlan-priO0..7Matches the the 3-bit VLAN Priority Code Point.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress/egress
source-macOyang:mac-addressMatches the source mac-address.

Applicable to ACL tables: Layer 3 IPv4/IPv6 ingress
dscpO0..63Matches the Differentiated Services Code Point in the IP header, allowing Quality of Service (QoS) differentiation with a range of 0 to 63.

Applicable to ACL tables: Layer 3 IPv4 or IPv6 ingress/egress

Tree Diagram

module: asternos-acl
+--rw access-lists

Tree Diagram

module: asternos-acl
rpcs:
+---x clear-counters-acl

Table of Properties

NameRequiredType/RangeDescription
clear-counters-aclO

Tree Diagram

module: asternos-acl
rpcs:
+---x show-counters-acl
+---w input
| +---w table-name* string
| +---w rule-id* string
+--ro output
+--ro data? <anydata>

Table of Properties

NameRequiredType/RangeDescription
show-counters-aclO
table-nameOstringACL table name.
rule-idOstringACL rule ID.
dataOThe rule counters for the specified parameter according to the value of input(table name, rule id).