Got it

IP prefix list vs ACL

Created: Sep 12, 2021 15:52:44Latest reply: Sep 12, 2021 18:40:58 206 3 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

What are the advantages of IP prefix list over ACL?


Featured Answers
Unicef
MVE Created Sep 12, 2021 16:28:33

Hello friend!

One advantage of IP prefix list over ACL is that routes can be matched against their mask. The following example shows the ip ip-prefix command used to configure an IPv4 prefix list:

ip ip-prefix ip-prefix-name [ index index-number ] { permit | deny } ipv4-address mask-length [ greater-equal greater-equal-value ] [ less-equal less-equal-value ]
In this command, ipv4-address mask-length [ greater-equal greater-equal-value ] [ less-equal less-equal-value ] defines the network ID and mask range of routes to be filtered.

https://support.huawei.com/enterprise/en/doc/EDOC1000178171/4d8bdd30/ip-prefix-list

Thanks!
View more
  • x
  • convention:

All Answers
Hello friend!

One advantage of IP prefix list over ACL is that routes can be matched against their mask. The following example shows the ip ip-prefix command used to configure an IPv4 prefix list:

ip ip-prefix ip-prefix-name [ index index-number ] { permit | deny } ipv4-address mask-length [ greater-equal greater-equal-value ] [ less-equal less-equal-value ]
In this command, ipv4-address mask-length [ greater-equal greater-equal-value ] [ less-equal less-equal-value ] defines the network ID and mask range of routes to be filtered.

https://support.huawei.com/enterprise/en/doc/EDOC1000178171/4d8bdd30/ip-prefix-list

Thanks!
View more
  • x
  • convention:

BAZ
BAZ MVE Author Created Sep 12, 2021 17:05:03

One of the biggest disadvantages with access list statements is the fact that the internal router's CPU must process each route update by comparting it against any ACL criteria. If the ACL criteria was lenghty or grew over time, then the CPU could be adversely affected.



Extended access list allow the use of wildcard bit masking to filter network prefixes and their associated masks to provide further filtering capabilities. They can also be used to filter addresses or prefixes based on the prefix length, but you must have a solid understandung of how to use wildcard masks to filter prefixes. Because of their complexity, IP prefix lists are easier to use when filtering prefix ranges.

View more
  • x
  • convention:

IP prefix imposes restrictions on network mask
ACL can't operate with mask, but with address only
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.