Explains how a virtual LPTS interface and compressed hybrid ACLs filter and police control and management plane traffic. Covers limitations, best practices, configuration, verification, and IPv6 AH and ESP support.
User-managed control and management plane access control lists (ACLs) are traffic-security controls that
-
create a virtual Local Packet Transport Services (LPTS) interface for router-bound traffic
-
apply compressed hybrid IPv4 and IPv6 ACLs to that interface, and
-
filter, police, prioritize, and log control and management plane traffic.
The data plane forwards user packets between interfaces. The control plane determines packet paths through routing protocols and related processes. The management plane provides device configuration and monitoring functions.
|
Feature Name |
Release Information |
Description |
|---|---|---|
| User Managed Control Plane and Management Plane ACL |
Release 7.3.3 Release 7.5.2 |
You can create a virtual LPTS interface and apply hybrid ACLs to it for inspecting traffic. This functionality lets you use the hybrid ACLs to filter and customize the control plane and management plane traffic. This feature modifies the following command: |
LPTS ACL mode
Use hw-module profile cef lpts acl to enable LPTS ACL mode. Apply one IPv4 ACL and one IPv6 ACL to the virtual LPTS interface with compression level 2.
Use no hw-module profile cef lpts acl to disable LPTS ACL mode.