Example 1 Limiting Access to a Specific Address Prefix Range

The following example shows how to install a permit untrusted ACL of source 12.34.0.0/16 for each signalling interface/port of a realm called access. Only packets from within the source address prefix range 12.34.0.0/16, destined for the signaling interfaces/port of the realm named access, are allowed. The packets go into untrusted queues until they are dynamically demoted or promoted based on their behavior. All other packets are denied/dropped.

  • Configure a realm called access and set the trust level to low and the address prefix to 12.34.0.0/16.
  • Configure a static ACL with a source prefix of 12.34.0.0/16 with the trust level set to low for the realm named access.