<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic G/C/B-Series f/w 6.61 ACL vs Policy Compatibility Guidelines in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/g-c-b-series-f-w-6-61-acl-vs-policy-compatibility-guidelines/m-p/48596#M537</link>
    <description>Article ID: 14999 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
G-Series, firmware 6.61.02.0007 and higher&lt;BR /&gt;
C5-Series, firmware 6.51.02.0018 and higher&lt;BR /&gt;
C3-Series, firmware 6.61.02.0007 and higher&lt;BR /&gt;
B5-Series, firmware 6.51.02.0018 and higher&lt;BR /&gt;
B3-Series, firmware 6.61.02.0007 and higher &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
When attempting to add an access-list (ACL) after Policy has been configured, the CLI editor issues errorpolicy is already configured on the device, please clear the policy to&lt;BR /&gt;
configure ACLWhen attempting to configure Policy after an access-list (ACL) has been configured, the CLI editor issues errorError, access list is configured.When attempting to enforce Policy after an access-list (ACL) has been configured, NetSight Policy Manager issues errorError : SNMP Error: Commit Failed (14).&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
With the above-stated products and firmware, IPv6 and MAC based ACLs are supported - but these use the same hardware resources as does Policy. &lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://extranet.enterasys.com/downloads/" target="_blank" rel="nofollow noreferrer noopener"&gt;Release notes&lt;/A&gt; state, in the 'What's New' section:Access Control Lists - Added support for IPv6 and MAC based ACLs. Added&lt;BR /&gt;
queue assignment action to ACLs. Note: ACLs are not supported&lt;BR /&gt;
simultaneously with Policy.The &lt;A href="http://extranet.enterasys.com/downloads/" target="_blank" rel="nofollow noreferrer noopener"&gt;CLI Guide&lt;/A&gt; states, in the 'Configuring Access Control Lists' chapter:IPv6 and MAC ACL Considerations&lt;BR /&gt;
In order to configure IPv6 or MAC ACLs, the switch must be put into&lt;BR /&gt;
access list "ipv6mode" with the access-list ipv6mode command. By&lt;BR /&gt;
default, this mode is disabled and the rule limits for standard and&lt;BR /&gt;
extended IPv4 ACLs remain unchanged.&lt;BR /&gt;
When ipv6mode is disabled ["no access-list ipv6mode"], IPv6 and MAC ACLs&lt;BR /&gt;
cannot be configured, and any existing IPv6 and MAC ACLs are removed&lt;BR /&gt;
from the configuration. This new mode cannot be enabled if Policy is&lt;BR /&gt;
configured on the switch, and Policy configurations will not be accepted&lt;BR /&gt;
when the switch is in ipv6mode.&lt;BR /&gt;
When ipv6mode is enabled or disabled, a system reset is required to&lt;BR /&gt;
change the mode. The configuration of ipv6mode is persistent and is&lt;BR /&gt;
shown in the running configuration.With these error messages, the system is enforcing an IPv4/IPv6 ACL vs Policy incompatibility. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Upgrade to firmware 6.61.08.0013 or higher (&lt;A href="http://bit.ly/1rViaUk" target="_blank" rel="nofollow noreferrer noopener"&gt;14480&lt;/A&gt;).&lt;BR /&gt;
The system will now enforce only an IPv6 ACL vs Policy incompatibility. &lt;BR /&gt;
&lt;BR /&gt;
When attempting to issue the 'access-list ipv6mode' command after Policy has been configured, the CLI editor issues errorpolicy is already configured on the device, please clear the policy to configure ACLWhen attempting to configure Policy after the 'access-list ipv6mode' command has been issued, the CLI editor issues errorError, access list ipv6mode is enabled.When attempting to enforce Policy after the 'access-list ipv6mode' command has been issued, NetSight Policy Manager issues errorError : SNMP Error: Commit Failed (14).Release notes state, in the 'Changes and Enhancements in 6.61.08.0013' section:18198  With the introduction of IPv6 ACLs, Policy and ACLs were&lt;BR /&gt;
prevented from being configured simultaneously. Policy configuration is&lt;BR /&gt;
now prevented only in "ipv6mode". These features use the same hardware&lt;BR /&gt;
resources and administrators are not guaranteed to reach published&lt;BR /&gt;
resource limits.Release notes state, in the 'Known Issues From Previous Releases' section:ACLs&lt;BR /&gt;
Access Control Lists (ACLs) use the same hardware resources as Policy&lt;BR /&gt;
rules and should not be used simultaneously with Policy.&lt;BR /&gt;
IPv6&lt;BR /&gt;
Enabling IPv6 and MAC ACLs with the "access-list ipv6mode" will reduce&lt;BR /&gt;
the total number of standard ACL rules currently supported. It will also&lt;BR /&gt;
prevent the use of Policy.Release notes also state the design limits for ACL Capacities (with and without the use of ipv6mode) and for Policy Capacities.</description>
    <pubDate>Wed, 27 Nov 2013 21:23:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-11-27T21:23:00Z</dc:date>
    <item>
      <title>G/C/B-Series f/w 6.61 ACL vs Policy Compatibility Guidelines</title>
      <link>https://community.extremenetworks.com/t5/faqs/g-c-b-series-f-w-6-61-acl-vs-policy-compatibility-guidelines/m-p/48596#M537</link>
      <description>Article ID: 14999 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
G-Series, firmware 6.61.02.0007 and higher&lt;BR /&gt;
C5-Series, firmware 6.51.02.0018 and higher&lt;BR /&gt;
C3-Series, firmware 6.61.02.0007 and higher&lt;BR /&gt;
B5-Series, firmware 6.51.02.0018 and higher&lt;BR /&gt;
B3-Series, firmware 6.61.02.0007 and higher &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
When attempting to add an access-list (ACL) after Policy has been configured, the CLI editor issues errorpolicy is already configured on the device, please clear the policy to&lt;BR /&gt;
configure ACLWhen attempting to configure Policy after an access-list (ACL) has been configured, the CLI editor issues errorError, access list is configured.When attempting to enforce Policy after an access-list (ACL) has been configured, NetSight Policy Manager issues errorError : SNMP Error: Commit Failed (14).&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
With the above-stated products and firmware, IPv6 and MAC based ACLs are supported - but these use the same hardware resources as does Policy. &lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://extranet.enterasys.com/downloads/" target="_blank" rel="nofollow noreferrer noopener"&gt;Release notes&lt;/A&gt; state, in the 'What's New' section:Access Control Lists - Added support for IPv6 and MAC based ACLs. Added&lt;BR /&gt;
queue assignment action to ACLs. Note: ACLs are not supported&lt;BR /&gt;
simultaneously with Policy.The &lt;A href="http://extranet.enterasys.com/downloads/" target="_blank" rel="nofollow noreferrer noopener"&gt;CLI Guide&lt;/A&gt; states, in the 'Configuring Access Control Lists' chapter:IPv6 and MAC ACL Considerations&lt;BR /&gt;
In order to configure IPv6 or MAC ACLs, the switch must be put into&lt;BR /&gt;
access list "ipv6mode" with the access-list ipv6mode command. By&lt;BR /&gt;
default, this mode is disabled and the rule limits for standard and&lt;BR /&gt;
extended IPv4 ACLs remain unchanged.&lt;BR /&gt;
When ipv6mode is disabled ["no access-list ipv6mode"], IPv6 and MAC ACLs&lt;BR /&gt;
cannot be configured, and any existing IPv6 and MAC ACLs are removed&lt;BR /&gt;
from the configuration. This new mode cannot be enabled if Policy is&lt;BR /&gt;
configured on the switch, and Policy configurations will not be accepted&lt;BR /&gt;
when the switch is in ipv6mode.&lt;BR /&gt;
When ipv6mode is enabled or disabled, a system reset is required to&lt;BR /&gt;
change the mode. The configuration of ipv6mode is persistent and is&lt;BR /&gt;
shown in the running configuration.With these error messages, the system is enforcing an IPv4/IPv6 ACL vs Policy incompatibility. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Upgrade to firmware 6.61.08.0013 or higher (&lt;A href="http://bit.ly/1rViaUk" target="_blank" rel="nofollow noreferrer noopener"&gt;14480&lt;/A&gt;).&lt;BR /&gt;
The system will now enforce only an IPv6 ACL vs Policy incompatibility. &lt;BR /&gt;
&lt;BR /&gt;
When attempting to issue the 'access-list ipv6mode' command after Policy has been configured, the CLI editor issues errorpolicy is already configured on the device, please clear the policy to configure ACLWhen attempting to configure Policy after the 'access-list ipv6mode' command has been issued, the CLI editor issues errorError, access list ipv6mode is enabled.When attempting to enforce Policy after the 'access-list ipv6mode' command has been issued, NetSight Policy Manager issues errorError : SNMP Error: Commit Failed (14).Release notes state, in the 'Changes and Enhancements in 6.61.08.0013' section:18198  With the introduction of IPv6 ACLs, Policy and ACLs were&lt;BR /&gt;
prevented from being configured simultaneously. Policy configuration is&lt;BR /&gt;
now prevented only in "ipv6mode". These features use the same hardware&lt;BR /&gt;
resources and administrators are not guaranteed to reach published&lt;BR /&gt;
resource limits.Release notes state, in the 'Known Issues From Previous Releases' section:ACLs&lt;BR /&gt;
Access Control Lists (ACLs) use the same hardware resources as Policy&lt;BR /&gt;
rules and should not be used simultaneously with Policy.&lt;BR /&gt;
IPv6&lt;BR /&gt;
Enabling IPv6 and MAC ACLs with the "access-list ipv6mode" will reduce&lt;BR /&gt;
the total number of standard ACL rules currently supported. It will also&lt;BR /&gt;
prevent the use of Policy.Release notes also state the design limits for ACL Capacities (with and without the use of ipv6mode) and for Policy Capacities.</description>
      <pubDate>Wed, 27 Nov 2013 21:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/g-c-b-series-f-w-6-61-acl-vs-policy-compatibility-guidelines/m-p/48596#M537</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-11-27T21:23:00Z</dc:date>
    </item>
  </channel>
</rss>

