Receive Access Control Lists rACLs

Receive access control lists (rACLs) are used to protect the Route Processor (RP) on highend routers from malicious or unwanted traffic that could degrade performance.

NOTE From the time this rACLs feature was originally introduced in 12.0 (22S for the Cisco 12000 series routers), numerous service providers have taken advantage of it. However, it is now available on other high-end routing platforms including the Cisco 7500 Series Routers and the Cisco 10000 Series Routers.

An rACL is just a standard or an extended ACL that controls the traffic sent by the various line cards to the RP. Because these high-end routers are designed in a distributed architecture, this type of ACL only affects the traffic destined to the RP and does not affect the transit traffic (traffic passing through the router).

rACLs comprise mainly permit statements that allow the protocols and specific sources that are expected to send traffic to the RP. These ACLs may also include deny statements to block specific unwanted traffic.

NOTE All ACLs have an implicit deny statement at the end.

The following is an example of an rACL. The rACL number is 123. It can be any number, however, all the access control entries (ACE) must use the same number. In the following example, the router IP address is 209.165.200.225. Only BGP and OSPF are permitted from the 192.168.10.0/24 network; all other traffic is denied.

!The following ACEs allow BGP traffic to the RP (209.165.200.225) access-list 123 permit tcp 192.168.10.0 0.0.0.255 host 209.165.200.225 eq bgp access-list 123 permit tcp 192.168.10.0 0.0.0.255 eq bgp host 209.165.200.225 !

!The following ACEs allow OSPF traffic to the RP (notice that the OSPF multicast address is !used instead of 209.165.200.225)

access-list 123 permit ospf 192.168.10.0 0.0.0.255 host 224.0.0.5

Optionally, you can deny specific traffic to protocols like UDP, TCP, and ICMP for tracking purposes. To do so, you can add the following lines to the ACL.

access-list 123 deny udp any any access-list 123 deny tcp any any access-list 123 deny icmp any any access-list 123 deny ip any any ip receive access-list 123

NOTE Do not forget to always apply the rACL with the ip receive access-list <num> command, as shown in the last line in the previous example. rACLs are created on the RP and then pushed to the line card processors. All received packets are first sent to the line card CPU; however, any packets requiring processing by the RP are then compared against the rACL before they are sent to the RP.

rACLs increase security by protecting the RP from direct attacks. However, because they are just filters, they do not provide rate limiting benefits that could control large volumes of traffic that may match the permitted sources and protocols. CoPP offers rate limiting techniques that replace the need for rACLs.

TIP When deploying the rACLs, always remember to start slowly. In other words, gradually improve security over time because, if you start too aggressively, your chance of dropping legitimate traffic increases.

Continue reading here: Scheduler Allocate Interval

Was this article helpful?

+1 0