Class iacl:Entry (CONCRETE)

Class ID:10977
Class Label: ACL entry of the CoPP Prefilter
Encrypted: false - Exportable: true - Persistent: true - Configurable: true - Subject to Quota: Disabled - Abstraction Layer: Logical Model - APIC NX Processing: Disabled
Write Access: [admin]
Read Access: [admin]
Creatable/Deletable: yes (see Container Mos for details)
Semantic Scope: Fabric
Semantic Scope Evaluation Rule: Parent
Monitoring Policy Source: Parent
Monitoring Flags : [ IsObservable: true, HasStats: true, HasFaults: true, HasHealth: true, HasEventRules: false ]

ACL entry of the CoPP Prefilter

Naming Rules
RN FORMAT: proto-{ipProto}-src-{[srcAddr]}-dst-{[dstAddr]}-srcFromP-{srcPortFrom}-srcToP-{srcPortTo}-dstFromP-{dstPortFrom}-dstToP-{dstPortTo}

    [1] PREFIX=proto- PROPERTY = ipProto


    [2] PREFIX=-src- PROPERTY = srcAddr


    [3] PREFIX=-dst- PROPERTY = dstAddr


    [4] PREFIX=-srcFromP- PROPERTY = srcPortFrom


    [5] PREFIX=-srcToP- PROPERTY = srcPortTo


    [6] PREFIX=-dstFromP- PROPERTY = dstPortFrom


    [7] PREFIX=-dstToP- PROPERTY = dstPortTo




DN FORMAT: 

[1] uni/infra/iaclspinep-{name}/proto-{ipProto}-src-{[srcAddr]}-dst-{[dstAddr]}-srcFromP-{srcPortFrom}-srcToP-{srcPortTo}-dstFromP-{dstPortFrom}-dstToP-{dstPortTo}

[3] uni/infra/iaclleafp-{name}/proto-{ipProto}-src-{[srcAddr]}-dst-{[dstAddr]}-srcFromP-{srcPortFrom}-srcToP-{srcPortTo}-dstFromP-{dstPortFrom}-dstToP-{dstPortTo}

                


Diagram

Super Mo: pol:Obj,
Container Mos: iacl:AProfile (deletable:yes),
Contained Mos: aaa:RbacAnnotation, tag:Annotation, tag:Tag,


Containers Hierarchies
[V] top:Root  This class represents the root element in the object hierarchy. All managed objects in the system are descendants of the Root element.
 ├
[V] fabric:Topology The root for IFC topology.
 
 ├
[V] fabric:Pod A pod.
 
 
 ├
[V] fabric:Node The root node for the APIC.
 
 
 
 ├
[V] ctx:Local The local Context.
 
 
 
 
 ├
[V] ctx:Application The context application.
 
 
 
 
 
 ├
[V] pol:Uni Represents policy definition/resolution universe.
 
 
 
 
 
 
 ├
[V] infra:Infra A container for all tenant infra configurations.
 
 
 
 
 
 
 
 ├
[V] iacl:SpineProfile  CoPP Prefilter policy that can be applied at SPINE nodes
 
 
 
 
 
 
 
 
 ├
[V] iacl:Entry  ACL entry of the CoPP Prefilter
[V] top:Root  This class represents the root element in the object hierarchy. All managed objects in the system are descendants of the Root element.
 ├
[V] pol:Uni Represents policy definition/resolution universe.
 
 ├
[V] infra:Infra A container for all tenant infra configurations.
 
 
 ├
[V] iacl:SpineProfile  CoPP Prefilter policy that can be applied at SPINE nodes
 
 
 
 ├
[V] iacl:Entry  ACL entry of the CoPP Prefilter
[V] top:Root  This class represents the root element in the object hierarchy. All managed objects in the system are descendants of the Root element.
 ├
[V] fabric:Topology The root for IFC topology.
 
 ├
[V] fabric:Pod A pod.
 
 
 ├
[V] fabric:Node The root node for the APIC.
 
 
 
 ├
[V] ctx:Local The local Context.
 
 
 
 
 ├
[V] ctx:Application The context application.
 
 
 
 
 
 ├
[V] pol:Uni Represents policy definition/resolution universe.
 
 
 
 
 
 
 ├
[V] infra:Infra A container for all tenant infra configurations.
 
 
 
 
 
 
 
 ├
[V] iacl:LeafProfile  CoPP Prefilter policy that can be applied at LEAF nodes
 
 
 
 
 
 
 
 
 ├
[V] iacl:Entry  ACL entry of the CoPP Prefilter
[V] top:Root  This class represents the root element in the object hierarchy. All managed objects in the system are descendants of the Root element.
 ├
[V] pol:Uni Represents policy definition/resolution universe.
 
 ├
[V] infra:Infra A container for all tenant infra configurations.
 
 
 ├
[V] iacl:LeafProfile  CoPP Prefilter policy that can be applied at LEAF nodes
 
 
 
 ├
[V] iacl:Entry  ACL entry of the CoPP Prefilter


Contained Hierarchy
[V] iacl:Entry  ACL entry of the CoPP Prefilter
 ├
[V] aaa:RbacAnnotation  RbacAnnotation is used for capturing rbac properties of any apic object Objects can append rbacannotations as Object->RbacAnnotation which is then checked for domain eligibility
 ├
[V] fault:Counts An immutable object that provides the number of critical, major, minor, and warning faults raised on its parent object and its subtree.
 ├
[V] fault:Delegate Exposes internal faults to the user. A fault delegate object can be defined on IFC (for example, for an endpoint group) and when the fault is raised (for example, under an endpoint policy on a switch), a fault delegate object is created on IFC under the specified object. A fault delegate object follows the lifecycle of the original fault instance object, being created, modified, or deleted based on the changes of the original fault.
 ├
[V] fault:Inst Contains detailed information of a fault. This object is attached as a child of the object on which the fault condition occurred. One instance object is created for each fault condition of the parent object. A fault instance object is identified by a fault code.
 
 ├
[V] aaa:RbacAnnotation  RbacAnnotation is used for capturing rbac properties of any apic object Objects can append rbacannotations as Object->RbacAnnotation which is then checked for domain eligibility
 
 ├
[V] tag:Annotation 
 
 ├
[V] tag:Tag 
 ├
[V] health:Inst A base class for a health score instance.(Switch only)
 ├
[V] tag:Annotation 
 ├
[V] tag:Tag 


Inheritance
[V] naming:NamedObject An abstract base class for an object that contains a name.
 ├
[V] pol:Obj Represents a generic policy object.
 
 ├
[V] iacl:Entry  ACL entry of the CoPP Prefilter


Stat Counters
scalar:Double GAUGE: copp:Permit:bytesRate(bytes-per-second)
           Bytes rate
           Deprecated Counter.
          Comments: NO COMMENTS
scalar:Uint64 COUNTER: copp:Permit:bytes(bytes)
           Bytes
           Deprecated Counter.
          Comments: Permitted bytes (Deprecated because HW is not supporting these)
scalar:Double GAUGE: copp:Permit:pktsRate(packets-per-second)
           Packets rate
          Comments: NO COMMENTS
scalar:Uint64 COUNTER: copp:Permit:pkts(packets)
           Packets
          Comments: Permitted packets


Stats
[V] iacl:Entry  ACL entry of the CoPP Prefilter
 ├
[V] copp:PermitAg15min A class that represents the most current aggregated statistics for Filter Counters in a 15 minute sampling interval. This class updates every 5 minutes.
 ├
[V] copp:PermitAg1d A class that represents the most current aggregated statistics for Filter Counters in a 1 day sampling interval. This class updates every hour.
 ├
[V] copp:PermitAg1h A class that represents the most current aggregated statistics for Filter Counters in a 1 hour sampling interval. This class updates every 15 minutes.
 ├
[V] copp:PermitAg1mo A class that represents the most current aggregated statistics for Filter Counters in a 1 month sampling interval. This class updates every day.
 ├
[V] copp:PermitAg1qtr A class that represents the most current aggregated statistics for Filter Counters in a 1 quarter sampling interval. This class updates every day.
 ├
[V] copp:PermitAg1w A class that represents the most current aggregated statistics for Filter Counters in a 1 week sampling interval. This class updates every day.
 ├
[V] copp:PermitAg1year A class that represents the most current aggregated statistics for Filter Counters in a 1 year sampling interval. This class updates every day.
 ├
[V] copp:PermitAgHist15min A class that represents historical aggregated statistics for Filter Counters in a 15 minute sampling interval. This class updates every 5 minutes.
 ├
[V] copp:PermitAgHist1d A class that represents historical aggregated statistics for Filter Counters in a 1 day sampling interval. This class updates every hour.
 ├
[V] copp:PermitAgHist1h A class that represents historical aggregated statistics for Filter Counters in a 1 hour sampling interval. This class updates every 15 minutes.
 ├
[V] copp:PermitAgHist1mo A class that represents historical aggregated statistics for Filter Counters in a 1 month sampling interval. This class updates every day.
 ├
[V] copp:PermitAgHist1qtr A class that represents historical aggregated statistics for Filter Counters in a 1 quarter sampling interval. This class updates every day.
 ├
[V] copp:PermitAgHist1w A class that represents historical aggregated statistics for Filter Counters in a 1 week sampling interval. This class updates every day.
 ├
[V] copp:PermitAgHist1year A class that represents historical aggregated statistics for Filter Counters in a 1 year sampling interval. This class updates every day.
 ├
[V] copp:PermitPart15min A class that represents the most current portion of the statistics for Filter Counters in a 15 minute sampling interval. This class updates every 5 minutes.
 ├
[V] copp:PermitPart1d A class that represents the most current portion of the statistics for Filter Counters in a 1 day sampling interval. This class updates every hour.
 ├
[V] copp:PermitPart1h A class that represents the most current portion of the statistics for Filter Counters in a 1 hour sampling interval. This class updates every 15 minutes.
 ├
[V] copp:PermitPart1mo A class that represents the most current portion of the statistics for Filter Counters in a 1 month sampling interval. This class updates every day.
 ├
[V] copp:PermitPart1qtr A class that represents the most current portion of the statistics for Filter Counters in a 1 quarter sampling interval. This class updates every day.
 ├
[V] copp:PermitPart1w A class that represents the most current portion of the statistics for Filter Counters in a 1 week sampling interval. This class updates every day.
 ├
[V] copp:PermitPart1year A class that represents the most current portion of the statistics for Filter Counters in a 1 year sampling interval. This class updates every day.
 ├
[V] copp:PermitPart5min A class that represents the most current portion of the statistics for Filter Counters in a 5 minute sampling interval. This class updates every 10 seconds.
 ├
[V] copp:PermitPartHist15min A class that represents historical portion of the statistics for Filter Counters in a 15 minute sampling interval. This class updates every 5 minutes.
 ├
[V] copp:PermitPartHist1d A class that represents historical portion of the statistics for Filter Counters in a 1 day sampling interval. This class updates every hour.
 ├
[V] copp:PermitPartHist1h A class that represents historical portion of the statistics for Filter Counters in a 1 hour sampling interval. This class updates every 15 minutes.
 ├
[V] copp:PermitPartHist1mo A class that represents historical portion of the statistics for Filter Counters in a 1 month sampling interval. This class updates every day.
 ├
[V] copp:PermitPartHist1qtr A class that represents historical portion of the statistics for Filter Counters in a 1 quarter sampling interval. This class updates every day.
 ├
[V] copp:PermitPartHist1w A class that represents historical portion of the statistics for Filter Counters in a 1 week sampling interval. This class updates every day.
 ├
[V] copp:PermitPartHist1year A class that represents historical portion of the statistics for Filter Counters in a 1 year sampling interval. This class updates every day.
 ├
[V] copp:PermitPartHist5min A class that represents historical portion of the statistics for Filter Counters in a 5 minute sampling interval. This class updates every 10 seconds.


Events
                iacl:Entry:creation__iacl_Entry
iacl:Entry:modification__iacl_Entry
iacl:Entry:deletion__iacl_Entry


Faults
                


Fsms
                


Properties Summary
Defined in: iacl:Entry
mo:Annotation
          string:Basic
annotation  (iacl:Entry:annotation)
           NO COMMENTS
iacl:addressIp
          address:Ip
dstAddr  (iacl:Entry:dstAddr)
           Destination Prefix to match, can be /32 or /128 for single host
l4:Port
          scalar:Uint16
dstPortFrom  (iacl:Entry:dstPortFrom)
           Destination Port Range, from field. Valid only for TCP/UDP cases
l4:Port
          scalar:Uint16
dstPortTo  (iacl:Entry:dstPortTo)
           Destination Port Range, to field. Valid only for TCP/UDP cases
mo:ExtMngdByType
          scalar:Bitmask32
extMngdBy  (iacl:Entry:extMngdBy)
           NO COMMENTS
l3:IpProt
          scalar:UByte
ipProto  (iacl:Entry:ipProto)
           The IP protocol.
reference:BinRef monPolDn  (iacl:Entry:monPolDn)
           The monitoring policy attached to this observable object.
iacl:addressIp
          address:Ip
srcAddr  (iacl:Entry:srcAddr)
           Source Prefix to match, can be /32 or /128 for single host
l4:Port
          scalar:Uint16
srcPortFrom  (iacl:Entry:srcPortFrom)
           Source Port Range, from field. Valid only for TCP/UDP cases
l4:Port
          scalar:Uint16
srcPortTo  (iacl:Entry:srcPortTo)
           Source Port Range, to field. Valid only for TCP/UDP cases
Defined in: pol:Obj
naming:Name
          string:Basic
name  (pol:Obj:name)
           Overrides:naming:NamedObject:name
           null
Defined in: naming:NamedObject
naming:NameAlias
          string:Basic
nameAlias  (naming:NamedObject:nameAlias)
           NO COMMENTS
Defined in: mo:Ownable
scalar:Uint16 uid  (mo:Ownable:uid)
           A unique identifier for this object.
Defined in: mo:Resolvable
mo:Owner
          scalar:Enum8
lcOwn  (mo:Resolvable:lcOwn)
           A value that indicates how this object was created. For internal use only.
Defined in: mo:Modifiable
mo:TStamp
          scalar:Date
modTs  (mo:Modifiable:modTs)
           The time when this object was last modified.
Defined in: mo:TopProps
mo:ModificationChildAction
          scalar:Bitmask32
childAction  (mo:TopProps:childAction)
           Delete or ignore. For internal use only.
reference:BinRef dn  (mo:TopProps:dn)
           A tag or metadata is a non-hierarchical keyword or term assigned to the fabric module.
reference:BinRN rn  (mo:TopProps:rn)
           Identifies an object from its siblings within the context of its parent object. The distinguished name contains a sequence of relative names.
mo:ModificationStatus
          scalar:Bitmask32
status  (mo:TopProps:status)
           The upgrade status. This property is for internal use only.
Properties Detail

annotation

Type: mo:Annotation
Primitive Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "128"
        Allowed Chars:
            Regex: [a-zA-Z0-9_.:-]+
    Comments:
NO COMMENTS



childAction

Type: mo:ModificationChildAction
Primitive Type: scalar:Bitmask32

Units: null
Encrypted: false
Access: implicit
Category: TopLevelChildAction
    Comments:
Delete or ignore. For internal use only.
Constants
deleteAll 16384u deleteAll NO COMMENTS
ignore 4096u ignore NO COMMENTS
deleteNonPresent 8192u deleteNonPresent NO COMMENTS
DEFAULT 0 --- This type is used to





dn

Type: reference:BinRef

Units: null
Encrypted: false
Access: implicit
Category: TopLevelDn
    Comments:
A tag or metadata is a non-hierarchical keyword or term assigned to the fabric module.



dstAddr

Type: iacl:addressIp
Primitive Type: address:Ip

Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Comments:
Destination Prefix to match, can be /32 or /128 for single host
Constants
defaultValue base::Ip("0.0.0.0/0") --- NO COMMENTS





dstPortFrom

Type: l4:Port
Primitive Type: scalar:Uint16

Like: copp:Filter:dstPortFrom
Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Range:  min: 0  max: 0xffff
    Comments:
Destination Port Range, from field. Valid only for TCP/UDP cases
Constants
unspecified 0 Unspecified NO COMMENTS
ftpData 20 ftp-data NO COMMENTS
smtp 25 smtp NO COMMENTS
dns 53 dns NO COMMENTS
http 80 http NO COMMENTS
pop3 110 pop3 NO COMMENTS
https 443 https NO COMMENTS
rtsp 554 rtsp NO COMMENTS
DEFAULT unspecified(0) Unspecified NO COMMENTS





dstPortTo

Type: l4:Port
Primitive Type: scalar:Uint16

Like: copp:Filter:dstPortTo
Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Range:  min: 0  max: 0xffff
    Comments:
Destination Port Range, to field. Valid only for TCP/UDP cases
Constants
unspecified 0 Unspecified NO COMMENTS
ftpData 20 ftp-data NO COMMENTS
smtp 25 smtp NO COMMENTS
dns 53 dns NO COMMENTS
http 80 http NO COMMENTS
pop3 110 pop3 NO COMMENTS
https 443 https NO COMMENTS
rtsp 554 rtsp NO COMMENTS
DEFAULT unspecified(0) Unspecified NO COMMENTS





extMngdBy

Type: mo:ExtMngdByType
Primitive Type: scalar:Bitmask32

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
NO COMMENTS
Constants
undefined 0u undefined NO COMMENTS
msc 1u msc NO COMMENTS
DEFAULT undefined(0u) undefined NO COMMENTS





ipProto

Type: l3:IpProt
Primitive Type: scalar:UByte

Like: copp:Filter:ipProto
Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Range:  min: (short)0  max: (short)255
    Comments:
The IP protocol.
Constants
unspecified 0 Unspecified Unspecified
icmp 1 icmp NO COMMENTS
igmp 2 igmp NO COMMENTS
tcp 6 tcp NO COMMENTS
egp 8 egp NO COMMENTS
igp 9 igp NO COMMENTS
udp 17 udp NO COMMENTS
icmpv6 58 icmpv6 NO COMMENTS
eigrp 88 eigrp NO COMMENTS
ospfigp 89 ospf NO COMMENTS
pim 103 pim NO COMMENTS
l2tp 115 l2tp NO COMMENTS
DEFAULT unspecified(0) Unspecified Unspecified





lcOwn

Type: mo:Owner
Primitive Type: scalar:Enum8

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
A value that indicates how this object was created. For internal use only.
Constants
local 0 Local NO COMMENTS
policy 1 Policy NO COMMENTS
replica 2 Replica NO COMMENTS
resolveOnBehalf 3 ResolvedOnBehalf NO COMMENTS
implicit 4 Implicit NO COMMENTS
DEFAULT local(0) Local NO COMMENTS





modTs

Type: mo:TStamp
Primitive Type: scalar:Date

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
The time when this object was last modified.
Constants
never 0ull never NO COMMENTS
DEFAULT never(0ull) never NO COMMENTS





monPolDn

Type: reference:BinRef

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
The monitoring policy attached to this observable object.



name

Type: naming:Name
Primitive Type: string:Basic

Overrides:naming:NamedObject:name
Units: null Encrypted: false Access: admin Category: TopLevelRegular Property Validators: Range: min: "0" max: "64" Allowed Chars: Regex: [a-zA-Z0-9_.:-]+
    Comments:
null



nameAlias

Type: naming:NameAlias
Primitive Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "63"
        Allowed Chars:
            Regex: [a-zA-Z0-9_.-]+
    Comments:
NO COMMENTS



rn

Type: reference:BinRN

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRn
    Comments:
Identifies an object from its siblings within the context of its parent object. The distinguished name contains a sequence of relative names.



srcAddr

Type: iacl:addressIp
Primitive Type: address:Ip

Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Comments:
Source Prefix to match, can be /32 or /128 for single host
Constants
defaultValue base::Ip("0.0.0.0/0") --- NO COMMENTS





srcPortFrom

Type: l4:Port
Primitive Type: scalar:Uint16

Like: copp:Filter:srcPortFrom
Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Range:  min: 0  max: 0xffff
    Comments:
Source Port Range, from field. Valid only for TCP/UDP cases
Constants
unspecified 0 Unspecified NO COMMENTS
ftpData 20 ftp-data NO COMMENTS
smtp 25 smtp NO COMMENTS
dns 53 dns NO COMMENTS
http 80 http NO COMMENTS
pop3 110 pop3 NO COMMENTS
https 443 https NO COMMENTS
rtsp 554 rtsp NO COMMENTS
DEFAULT unspecified(0) Unspecified NO COMMENTS





srcPortTo

Type: l4:Port
Primitive Type: scalar:Uint16

Like: copp:Filter:srcPortTo
Units: null
Encrypted: false
Naming Property -- [NAMING RULES]
Access: naming
Category: TopLevelRegular
Property Validators:
    Range:  min: 0  max: 0xffff
    Comments:
Source Port Range, to field. Valid only for TCP/UDP cases
Constants
unspecified 0 Unspecified NO COMMENTS
ftpData 20 ftp-data NO COMMENTS
smtp 25 smtp NO COMMENTS
dns 53 dns NO COMMENTS
http 80 http NO COMMENTS
pop3 110 pop3 NO COMMENTS
https 443 https NO COMMENTS
rtsp 554 rtsp NO COMMENTS
DEFAULT unspecified(0) Unspecified NO COMMENTS





status

Type: mo:ModificationStatus
Primitive Type: scalar:Bitmask32

Units: null
Encrypted: false
Access: implicit
Category: TopLevelStatus
    Comments:
The upgrade status. This property is for internal use only.
Constants
created 2u created In a setter method: specifies that an object should be created. An error is returned if the object already exists.
In the return value of a setter method: indicates that an object has been created.
modified 4u modified In a setter method: specifies that an object should be modified
In the return value of a setter method: indicates that an object has been modified.
deleted 8u deleted In a setter method: specifies that an object should be deleted.
In the return value of a setter method: indicates that an object has been deleted.
DEFAULT 0 --- This type controls the life cycle of objects passed in the XML API.

When used in a setter method (such as configConfMo), the ModificationStatus specifies whether an object should be created, modified, deleted or removed.
In the return value of a setter method, the ModificationStatus indicates the actual operation that was performed. For example, the ModificationStatus is set to "created" if the object was created. The ModificationStatus is not set if the object was neither created, modified, deleted or removed.

When invoking a setter method, the ModificationStatus is optional:
If a setter method such as configConfMo is invoked and the ModificationStatus is not set, the system automatically determines if the object should be created or modified.






uid

Type: scalar:Uint16

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
A unique identifier for this object.