Policy lists rule criteria

Last Updated : Nov 06, 2012 |

Rules work in the following ways, depending on the type of list and the type of information in the packet:

  • Layer 4 rules in an access control list with a Permit operation are applied to non-initial fragments

  • Layer 4 rules in an access control list with a Deny operation are not applied to non-initial fragments, and the device continues checking the next IP rule. This is to prevent cases in which fragments that belong to other L4 sessions may be blocked by the other L4 session which is blocked.

  • Layer 3 rules apply to non-initial fragments

  • Layer 3 rules that include the fragment criteria do not apply to initial fragments or non-fragment packets

  • Layer 3 rules that do not include the fragment criteria apply to initial fragments and non-fragment packets

  • Layer 4 rules apply to initial fragments and non-fragment packets

  • Layer 3 and Layer 4 rules in QoS and policy-based routing lists apply to non-initial fragments