Restrictions for IPv6 Object Groups for ACLs
-
Object group-based ACLs support only Layer 3 interfaces (such as routed interfaces and VLAN interfaces). Object group-based ACLs do not support Layer 2 features such as VLAN ACLs (VACLs) or port ACLs (PACLs).
-
Object group-based ACLs are not supported with IPsec.
-
The highest number of object group-based ACEs supported in an ACL is 2048.
-
Empty object groups are automatically deleted.
-
The object-group needs to be created before referencing it in the accesslist. An object-group cannot be deleted when it is referenced by other features, like access lists.
-
Object groups that contain ACL entries are skipped, if an ACL match is performed for a packet flow.
-
Use the same IPv6 address notation when you create and update an IPv6 network object group. If you create the object group with expanded addresses, use expanded addresses for later updates. If you create it with compressed addresses, use compressed addresses for later updates. The device treats an equivalent prefix in a different notation as a duplicate entry. The duplicate entry can cause the configuration commit or controller deployment to fail.
Feedback