Extended ACLs and Extended ACL6s
Configuring Extended ACLs and Extended ACL6s
-
Create an extended ACL or ACL6. Create an extended ACL or ACL6 to either allow, deny, or bridge a packet. You can specify an IP address or range of IP addresses to match against the source or destination IP addresses of the packets. You can specify a protocol to match against the protocol of incoming packets.
-
(Optional) Modify an extended ACL or ACL6. You can modify extended ACLs or ACL6s that you previously created. Or, if you want to temporarily take one out of use you can disable it, and later reenable it.
-
Apply extended ACLs or ACL6s. After you create, modify, disable or reenable, or delete an extended ACL or ACL6, you must apply the extended ACLs or ACL6s to activate them.
-
(Optional) Renumber the priorities of extended ACLs or ACL6s. If you have configured ACLs with priorities that are not multiples of 10 and want to restore the numbering to multiples of 10, use the renumber procedure.
CLI procedures
-
disable ns acl \<aclname>
-
enable ns acl \<aclname>
-
disable ns acl6 \<aclname>
-
enable ns acl6 \<aclname>
-
apply ns acls
-
apply ns acls6
-
renumber ns acls
-
renumber ns acls6
GUI procedures
-
Navigate to System > Network > ACLs and, on the Extended ACLs tab, add a new extended ACL or edit an existing extended ACL. To enable or disable an existing extended ACL, select it, and then select Enable or Disable from the Action list.
-
Navigate to System > Network > ACLs and, on the Extended ACL6s tab, add a new extended ACL6 or edit an existing extended ACL6. To enable or disable an existing extended ACL6, select it, and then select Enable or Disable from the Action list.
-
Navigate to System > Network > ACLs and, on the Extended ACLs tab, in the Action list, click Apply.
-
Navigate to System > Network > ACLs and, on the Extended ACL6s tab, in the Action list, click Apply.
-
Navigate to System > Network > ACLs and, on the Extended ACLs tab, in the Action list, click Renumber Priority (s).
-
Navigate to System > Network > ACLs and, on the Extended ACL6s tab, in the Action list, click Renumber Priority (s).
Sample Configurations
Logging extended ACLs
nslog file, depending on the type of global logging (syslog or nslog) enabled.
CLI procedures
GUI procedures
-
Navigate to System > Network > ACLs and, on the Extended ACLs tab, open the extended ACL.
-
Set the following parameters:
-
Log State—Enable or disable logging of events related to the extended ACL rule. The log messages are stored in the configured
syslog or auditlogserver. -
Log Rate Limit—Maximum number of log messages to be generated per second per packet flow. If you set this parameter, you must enable the Log State parameter.
-
Sample configuration
> set ns acl restrict -logstate ENABLED -ratelimit 120
Warning: ACL modified, apply ACLs to activate change
> apply ns acls
Done
Logging extended ACL6s
nslog file, depending on the type of logging (syslog or nslog) that you have configured in the NetScaler appliance.
-
Source IP
-
Destination IP
-
Source port
-
Destination port
-
Protocol (TCP or UDP)
CLI procedures
-
To configure logging while adding the extended ACL6 rule, at the command prompt, type:
-
apply acls6
-
To configure logging for an existing extended ACL6 rule, at the command prompt, type:
-
apply acls6
GUI procedures
-
Navigate to System > Network > ACLs and, then click the Extended ACL6s tab.
-
Set the following parameters while adding, or modifying an existing extended ACL6 rule.
-
Log State — Enable or disable logging of events related to the extended ACL6s rule. The log messages are stored in the configured syslog or
auditlogserver. -
Log Rate Limit—Maximum number of log messages to be generated per second per packet flow. If you set this parameter, you must enable the Log State parameter.
-
Sample configuration
> set acl6 ACL6-1 -logstate ENABLED -ratelimit 120
Done
> apply acls6
Done
Displaying extended ACLs and extended ACL6s statistics
| Statistic | Specifies |
|---|---|
| Allow ACL matches | Packets matching ACLs with processing mode set to ALLOW. The NetScaler processes these packets. |
| NAT ACL matches | Packets matching a NAT ACL, resulting in a NAT session. |
| Deny ACL matches | Packets dropped because they match ACLs with processing mode set to DENY. |
| Bridge ACL matches | Packets matching a bridge ACL, which in transparent mode bypasses service processing. |
| ACL matches | Packets matching an ACL. |
| ACL misses | Packets not matching any ACL. |
| ACL Count | Total number of ACL rules configured by users. |
| Effective ACL Count | Total number of effective ACL configured internally. For an extended ACL with a range of IP addresses, the NetScaler appliance internally creates an extended ACL for each IP address. For example, for an extended ACL with 1000 IPv4 addresses (range or dataset), the NetScaler internally creates 1000 extended ACLs. |
CLI procedures
-
stat ns acl
-
stat ns acl6
GUI procedures
-
Navigate to System > Network > ACLs, on the Extended ACLs tab, select the extended ACL, and click Statistics.
-
Navigate to System > Network > ACLs, on the Extended ACL6s tab, select the extended ACL, and click Statistics.
Stateful ACLs
-
The NetScaler appliance must allow requests initiated from internal clients and the related responses from the Internet.
-
The appliance must drop the packets from the Internet that are not related to any client connections.
Before you begin
-
The NetScaler appliance supports stateful ACL rules and stateful ACL6 rules.
-
In a high availability setup, the sessions for a stateful ACL rule are not synchronized to the secondary node.
-
You cannot configure an ACL rule as stateful if the rule is bound to any NetScaler NAT configuration. Some examples of NetScaler NAT configurations are:
-
RNAT
-
Large Scale NAT (large scale NAT44, DS-Lite, large scale NAT64)
-
NAT64
-
Forwarding session
-
-
You cannot configure an ACL rule as stateful if TTL and Established parameters are set for this ACL rule.
-
The sessions created for a stateful ACL rule continue to exist until time out irrespective of the following ACL operations:
-
Remove ACL
-
Disable ACL
-
Clear ACL
-
-
Stateful ACLs are not supported for the following protocols:
-
Active FTP
-
TFTP
-
Configure stateful IPv4 ACL rules
-
To enable the stateful parameter while adding an ACL rule, at the command prompt, type:
-
add acl \<lname> ALLOW -stateful (ENABLED | DISABLED)
-
apply acls
-
show acl \<name>
-
-
To enable the stateful parameter of an existing ACL rule, at the command prompt, type:
-
set acl \<name> -stateful (ENABLED | DISABLED)
-
apply acls
-
show acl \<name>
-
-
Navigate to System > Network > ACLs and, on the Extended ACLs tab.
-
Enable the Stateful parameter while adding, or modifying an existing ACL rule.
Sample configuration
> add acl ACL-1 allow -srciP 1.1.1.1 -stateful Yes
Done
> apply acls
Done
> show acl
1) Name: ACL-1
Action: ALLOW Hits: 0
srcIP = 1.1.1.1
destIP
srcMac:
Protocol:
Vlan: Interface:
Active Status: ENABLED Applied Status: NOTAPPLIED
Priority: 10 NAT: NO
TTL:
Log Status: DISABLED
Forward Session: NO
Stateful: YES
Configure stateful ACL6 rules
-
To enable the stateful parameter while adding an ACL6 rule, at the command prompt, type:
-
add acl6 \<name> ALLOW -stateful ( ENABLED | DISABLD )
-
apply acls6
-
show acl6 \<name>
-
-
To enable the stateful parameter of an existing ACL6 rule, at the command prompt, type:
-
set acl6 \<name> -stateful ( ENABLED | DISABLED )
-
apply acls6
-
show acl6 \<name>
-
-
Navigate to System > Network > ACLs and, on the Extended ACL6s tab.
-
Enable the Stateful parameter while adding, or modifying an existing ACL6 rule.
Sample configuration
> add acl6 ACL6-1 allow -srcipv6 1000::1 –stateful Yes
Done
> apply acls6
Done
> show acl6
1) Name: ACL6-1
Action: ALLOW Hits: 0
srcIPv6 = 1000::1
destIPv6
srcMac:
Protocol:
Vlan: Interface:
Active Status: ENABLED Applied Status: NOTAPPLIED
Priority: 10 NAT: NO
TTL:
Forward Session: NO
Stateful: YES
Dataset based extended ACLs
-
IPv4 address (for specifying the source IP address or the destination IP address or both for an ACL rule)
-
number (for specifying the source port or the destination port or both for an ACL rule)
Before you begin
-
Make sure that you are familiar with the dataset feature of a NetScaler appliance. For more information about datasets, see Pattern sets and data sets.
-
The NetScaler appliance supports datasets only for IPv4 extended ACLs.
-
The NetScaler appliance supports only the following types of datasets for the extended ACLs:
-
IPv4 address
-
number
-
-
The NetScaler appliance supports dataset based extended ACLs for all NetScaler set ups: standalone, high availability, and cluster.
-
For an extended ACL with datasets containing ranges, the NetScaler appliance internally creates an extended ACL for each combination of the dataset values.
-
Example 1: For an IPv4 dataset based extended ACL with 1000 IPv4 addresses bound to the dataset, and the dataset is set to the source IP parameter, the NetScaler appliance internally creates 1000 extended ACLs.
-
Example 2: A dataset based extended ACL with following parameters set:
-
Source IP is set to a dataset containing 5 IP addresses.
-
Destination IP is set to a dataset containing 5 IP addresses.
-
Source port is set to a dataset containing 5 ports.
-
Destination port is set to a dataset containing 5 ports.
The NetScaler appliance internally creates 625 extended ACLs. Each of these internal ACLs contains a unique combination of the above mentioned four parameter values. -
-
The NetScaler appliance supports a maximum of 10K extended ACLs. For an IPv4 dataset based extended ACL with a range of IP addresses bound to the dataset, the NetScaler appliance stops creating internal ACLs once the total number of extended ACLs reaches the maximum limit.
-
The following counters are present as part of the extended ACL statistics:
-
ACL count. Total number of ACL rules configured by users.
-
Effective ACL count. Total number of effective ACL rules that the NetScaler appliance configures internally.
For more information, see Displaying extended ACL and extended ACL6s Statistics. -
-
-
The NetScaler appliance does not support
setandunsetoperations for associating/dissociating datasets with the parameters of an extended ACL. You can set the ACL parameters to a dataset only during theaddoperation.
Configure dataset based extended ACLs
-
Add a dataset. A dataset is an array of indexed patterns of types: number (integer), IPv4 address, or IPv6 address. In this task, you create a type of dataset, for example, a dataset of type IPv4.
-
Bind values to the dataset. Specify a value or a range of values to the dataset. The specified values must be of the same type as the dataset type. For example, you can specify an IPv4 address, or an IPv4 address range, or an IPv4 address range in CIDR notation to an IPv4 dataset.
-
Add an extended ACL and set ACL paramters to the dataset. Add an extended ACL and set the required ACL parameters to the dataset. This setting results in the parameters set to the values specified in the dataset.
-
Apply extended ACLs. Apply the ACLs to activate any new or modified extended ACLs.
-
add policy dataset \<name> \<type>
-
show policy dataset
-
show policy dataset
-
show acls
-
apply acls
Sample configuration
DATASET_IP_ACL_1 and DATASET_IP_ACL_2 are created. Two port datasets DATASET_PORT_ACL_1 and DATASET_PORT_ACL_1 are created.
DATASET_IP_ACL_1. Two IPv4 address ranges: (198.51.100.15 - 45) and (203.0.113.60-90) are bound to DATASET_IP_ACL_2. DATASET_IP_ACL_1 is then specified to the srcIP parameter, and DATASET_IP_ACL_1 to the destIP parameter of the extended ACL ACL-1.
DATASET_PORT_ACL_1. Two port ranges: (5001 - 5040) and (8001 - 8040) are bound to DATASET-PORT-ACL-2. DATASET_IP_ACL_1 is then specified to the srcIP parameter, and DATASET_IP_ACL_1 to the destIP parameter of the extended ACL ACL-1.
add policy dataset DATASET_IP_ACL_1 IPV4
add policy dataset DATASET_IP_ACL_2 IPV4
add policy dataset DATASET_PORT_ACL_1 NUM
add policy dataset DATASET_PORT_ACL_2 NUM
bind dataset DATASET_IP_ACL_1 192.0.2.30
bind dataset DATASET_IP_ACL_1 192.0.2.60
bind dataset DATASET_IP_ACL_2 198.51.100.15 -endrange 198.51.100.45
bind dataset DATASET_IP_ACL_2 203.0.113.1/24
bind dataset DATASET_PORT_ACL_1 2001
bind dataset DATASET_PORT_ACL_1 2004
bind dataset DATASET_PORT_ACL_2 5001 -endrange 5040
bind dataset DATASET_PORT_ACL_2 8001 -endrange 8040
add ns acl ACL-1 ALLOW -srcIP DATASET_IP_ACL_1 -destIP DATASET_IP_ACL_2
-srcPort DATASET_PORT_ACL_1 -destPort DATASET_PORT_ACL_2 –protocol TCP