Question

ACL Rules and NCLU

  • 26 February 2020
  • 1 reply
  • 91 views

Hi all,

I have some problems to create ACL rules with NCLU. I would like to know:

  • Has the NCLU ACL rules the same limitation as iptables rules
  • Is NCLU interface outbound filter hardware accelerated
  • Are NCLU outbound filters the same as iptables output filters

I would also be appreciate for any document or link to more detailed documentation for creating Cumulus NCLU filters.
 

Thanks, Ales


1 reply

Userlevel 5

NCLU just provides a wrapper for IPtables. Most folks still use IPtables today the ACL documentation had not previously been extended to cover all the new ACL functionality covered in NCLU.

 

  • Has the NCLU ACL rules the same limitation as iptables rules
    YES
  • Is NCLU interface outbound filter hardware accelerated
    YES
  • Are NCLU outbound filters the same as iptables output filters
    No -- NCLU outbound filters use the FORWARD chain in the filter table matching on the egress-interface. Iptables Output filters match the Output chain matching on the egress-interface.

Reply