Access control lists
-
Usage guidelines
-
How to configure ACLs
-
Other actions for ACL rules
-
Troubleshooting
Usage guidelines
-
When you upgrade the SDX appliance to release 11.0 57.19, the ACL feature is disabled by default.
-
SDX administrators can control only inbound packets through ACL on the SDX appliance.
-
If you use NetScaler Console to manage your SDX appliance, you must create appropriate ACL rules to allow communication between MAS and the SDX Management Service.
-
Any other configurations on the SDX appliance such as provisioning or deleting VPXs, adding/deleting external servers, SNMP management, do not require any changes in the existing ACL configuration. Communication with these entities is taken care of by the Management Service.
How to Configure an ACL
-
Enable the ACL feature
-
Create an ACL rule
-
Enable the ACL rule
Enable the ACL feature
-
To enable the ACL feature, log on to the SDX Management Service GUI and navigate to Configuration > System > ACL.
-
By using the toggle button, turn on the ACL feature.ACL rule
Create an ACL rule
-
On the ACL page, click Create Rule.
-
The Create Rule window opens. Add the details listed in the following table.|Property|Description| |--|--| |Name|Add a name.| |Protocol|Select a protocol from the menu. By default, TCP is selected. You can select ANY to allow all protocols.| |Source IP Address/Subnet|Specify the source IP address or source subnet to which the rule applies. Select ANY if the rule must be applied to all incoming traffic.| |Destination IP|The SDX Management Service IP address is autopopulated as the destination IP. This field cannot be edited.| |Destination port|Specify the destination port to which the rule applies. Select ANY if the rule applies to all destination ports.| |Action|Select the action for the rule, which is Allow or Deny.| |Priority|Assign priority to specify the order in which the rule is to be evaluated. Priority numbers determine the order in which ACL rules are matched against an incoming packet. A lower priority number has a higher priority. For example, priority number 1 has a higher priority than priority number 1. If none of the rules match with the incoming packet, then the packet is blocked.|
-
Click OK to create the rule.Figure: An example of an ACL ruleSDX ACL ruleAfter the rule is created, it is in the disabled state. To make the rule effective, you must enable the rule.Note:To enable a rule, the ACL feature must be enabled. If the feature is disabled, and you attempt to enable an ACL rule, a message "ACL is not running" appears.
Enable an ACL rule
-
Hover your mouse over the rule that you want to enable and click the circle with three dots.
-
From the menu, select Enable.
-
Alternatively, select the radio button for that rule and click the Enable tab.
-
At the prompt, click Yes to confirm.
Other actions for ACL rules
-
Disable an ACL rule
-
Edit an ACL rule
-
Delete an ACL rule
-
Renumber the priority of ACL rules
Disable an ACL rule
-
Hover the mouse over the rule that you want to disable and select the circle with three dots.
-
Click Disable from the list.
-
Alternatively, select the radio button for that rule and click the Disable tab.
-
Click Yes to confirm.
Edit an ACL rule
-
Hover the mouse over the rule that you want to edit and select the circle with three dots.
-
Click Edit Rule from the list. The Modify Rule window opens.
-
Alternatively, select the radio button for that rule and click the Edit Rule tab. The Modify Rule window opens
-
Make the edits and click OK.
Delete an ACL rule
-
Ensure that the rule is in the disabled state.
-
Hover the mouse over the rule that you want to delete and select the circle with three dots. Click Delete Rule from the list.
-
Alternatively, select the radio button for that rule and click the Delete Rule tab.
-
Click Yes to confirm.
Renumber priorities of ACL rules
-
Hover the mouse over the rule that you want to renumber the priorities for and select the circle with three dots. Click Renumber Priority(s) from the list.
-
Alternatively, select the radio button for that rule and click the Select Action tab.
-
Select Renumber Priority(s).
-
The SDX Management Service automatically assigns new priority numbers, which are multiples of 10, to all the existing rules.
-
Edit the rules to assign priority numbers according to your requirement. See the "To edit an ACL rule" section for more information about how to edit a rule.
Troubleshooting
-
Log on to the Citrix Hypervisor™ management IP address by using SSH and your "root" account.
-
Log on to the console of the Management Service VM by using admin privileges.
-
Run the command
pfctl –d. -
Log on to the Management Service through the GUI and reconfigure the ACL accordingly.