This topic describes how TCP flags are used in access control lists (ACLs) to permit or deny packets on the Cisco 8000 Series Router.
The Transmission Control Protocol (TCP) flags are indicators used in ACLs that
-
influence the flow of data across a TCP connection
-
provide information about the connection state, and
-
control packet transfer behavior.
The Transmission Control Protocol (TCP) is one of the most widely used protocols for data transmission in networks. The TCP header contains several one-bit boolean fields known as flags used to influence the flow of data across a TCP connection. TCP packets use TCP flags during a packet transfer to indicate connection state or provide additional information about the packet transfer. This list describes the capabilities of ACLs when filtering packets based on TCP flags:
-
ACLs allow the creation of Access Control Entries (ACEs) that filter packets based on whether a TCP flag is set or not.
-
ACLs enable filtering of packets based on the presence or absence of any single TCP flag or a combination of multiple TCP flags.
-
ACLs provide increased flexibility in packet filtering and enhance security by permitting, for example, packets with a SYN flag to ensure verified sources.
The TCP flags include SYN, ACK, FIN, RST, URG, PSH, and EST, each serving to indicate specific connection states or provide additional packet transfer information.
Feature History Table
|
Feature Name |
Release Information |
Description |
|---|---|---|
|
TCP Flags in Egress IPv6 ACLs |
Release 26.2.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]):* *This feature is supported on:
|
|
TCP Flags in Egress IPv6 ACLs |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
TCP Flags in Egress IPv6 ACLs |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*) This feature is supported on:
|
|
TCP Flags in Egress IPv6 ACLs |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
|
TCP Flags in Egress IPv6 ACLs |
Release 7.3.15 |
You can configure an egress IPv6 ACL that permits or denies packets on the basis of TCP flags set in them. Through this feature, you can restrict and manage traffic streams thereby enhancing network security. The following commands are updated: |