Kaspersky SD-WAN

Creating an access-control list (ACL)

Expand all | Collapse all

You can create an access control list on an individual CPE device or on all devices that use the CPE template. To create an access control list, use the following instructions:

  • Creating an access control list on an individual CPE device.

    To create an access control list on an individual CPE device:

    1. In the menu, go to the SD-WAN section.

      By default, the CPE subsection is displayed with a table of CPE devices.

    2. Click the CPE device.

      The settings area is displayed in the lower part of the page. You can expand the settings area to fill the entire page by clicking the expand button .

    3. Select the Routing Filters tab.

      The Access control lists tab, which is selected by default, displays the table of access control lists.

    4. Select the Override check box to ignore the applied CPE template and make the settings in the selected tab editable. This check box is cleared by default.
    5. Click + Access control list.
    6. This opens a window; in that window, in the Name field, enter the name of the access control list. Maximum length: 50 characters. Do not use spaces in this field.
    7. Click + Add rule to add a rule to the access control list. You can add multiple rules.
    8. In the Sequence field, enter the sequential number of the rule. The rule with the lowest number is processed first. Range of values: 1 to 4,294,967,295.
    9. In the Network drop-down list, select the type of the rule:
      • Any network for a rule that allows or denies advertising of any networks.
      • IP/mask for a rule that allows or denies the advertising of a specific network. This is the default setting.
    10. If in the Network drop-down list, you selected IP/mask, in the field that is displayed, enter the IP address and the network prefix.
    11. In the Action drop-down list, select the action that the rule must apply to routes:
      • Permitto allow route advertising. This is the default setting.
      • Deny to deny route advertising.
    12. Click Create.

      The access control list is created and displayed in the table.

    13. In the upper part of the settings area, click Save to save the configuration of the CPE device.
  • Creating an access control list on all devices that use the CPE template.

    To create an access control list on all devices that use the CPE template:

    1. In the menu, go to the SD-WAN → CPE templates subsection.

      A table of CPE templates is displayed.

    2. Click the CPE template.

      The settings area is displayed in the lower part of the page. You can expand the settings area to fill the entire page by clicking the expand button .

    3. Select the Routing Filters tab.

      The Access control lists tab, which is selected by default, displays the table of access control lists.

    4. Click + Access control list.
    5. This opens a window; in that window, in the Name field, enter the name of the access control list. Maximum length: 50 characters. Do not use spaces in this field.
    6. Click + Add rule to add a rule to the access control list. You can add multiple rules.
    7. In the Sequence field, enter the sequential number of the rule. The rule with the lowest number is processed first. Range of values: 1 to 4,294,967,295.
    8. In the Network drop-down list, select the type of the rule:
      • Any network for a rule that allows or denies advertising of any networks.
      • IP/mask for a rule that allows or denies the advertising of a specific network. This is the default setting.
    9. If in the Network drop-down list, you selected IP/mask, in the field that is displayed, enter the IP address and the network prefix.
    10. In the Action drop-down list, select the action that the rule must apply to routes:
      • Permitto allow route advertising. This is the default setting.
      • Deny to deny route advertising.
    11. Click Create.

      The access control list is created and displayed in the table.

    12. In the upper part of the settings area, click Save to save the configuration of the CPE template.
Page top
[Topic 244831]