This topic describes how the IP Extended Access Lists with Fragment Control feature provides granular control over non-initial IP fragments when you apply an IP extended access list.
Non-fragmented packets and the initial fragments of a packet are processed by IP extended access lists (if you apply this access list), but non-initial fragments are permitted by default.
The IP Extended Access List with Fragment Control is a configuration feature that
-
provides granular filtering control over non-initial IP fragments
-
applies Layer 3-specific access-list entries to non-initial packet fragments, and
-
utilizes an optional fragments keyword to manage how the system evaluates packet segments.
This feature adds the optional fragments keyword to these IP access list commands:
-
deny
-
permit
Behavior of access-list entries with and without the fragments keyword
|
If the access-list entry has... |
Then... |
|---|---|
|
No fragments keyword and all of the access-list entry information matches |
For an access-list entry containing only Layer 3 information:
For an access-list entry containing Layer 3 and Layer 4 information:
|
|
The fragments keyword and all of the access-list entry information matches |
The access-list entry is applied only to non-initial fragments.
|