{"id":18678170,"url":"https://github.com/srl-labs/srl-acl-lab","last_synced_at":"2025-08-27T02:10:33.419Z","repository":{"id":244124279,"uuid":"814295421","full_name":"srl-labs/srl-acl-lab","owner":"srl-labs","description":"Get to know ACLs on SR Linux","archived":false,"fork":false,"pushed_at":"2024-12-15T20:19:43.000Z","size":2621,"stargazers_count":2,"open_issues_count":0,"forks_count":1,"subscribers_count":4,"default_branch":"main","last_synced_at":"2025-02-13T15:14:01.605Z","etag":null,"topics":["clab-topo","codespaces","srlinux"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/srl-labs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-06-12T18:11:46.000Z","updated_at":"2024-12-15T20:19:47.000Z","dependencies_parsed_at":"2024-06-13T02:20:22.185Z","dependency_job_id":"52a2f361-72aa-4638-99c6-078094b5ee42","html_url":"https://github.com/srl-labs/srl-acl-lab","commit_stats":null,"previous_names":["srl-labs/srl-acl-lab"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/srl-labs%2Fsrl-acl-lab","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/srl-labs%2Fsrl-acl-lab/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/srl-labs%2Fsrl-acl-lab/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/srl-labs%2Fsrl-acl-lab/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/srl-labs","download_url":"https://codeload.github.com/srl-labs/srl-acl-lab/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":239525504,"owners_count":19653340,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["clab-topo","codespaces","srlinux"],"created_at":"2024-11-07T09:36:15.777Z","updated_at":"2025-02-18T18:26:09.689Z","avatar_url":"https://github.com/srl-labs.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# Access Control Lists on SR Linux\n\n[![Discord][discord-svg]][discord-url] [![DevPod][devpod-svg]][devpod-url] [![Codespaces][codespaces-svg]][codespaces-url]  \n![w212][w212][Learn more](https://containerlab.dev/macos/#devpod)![w90][w90][Learn more](https://containerlab.dev/manual/codespaces)\n\n[discord-svg]: https://gitlab.com/rdodin/pics/-/wikis/uploads/b822984bc95d77ba92d50109c66c7afe/join-discord-btn.svg\n[discord-url]: https://discord.gg/tZvgjQ6PZf\n[devpod-svg]: https://gitlab.com/rdodin/pics/-/wikis/uploads/dfc36636ecaa60f3e70340686d5800db/open-in-devpod-btn.svg\n[devpod-url]: https://devpod.sh/open#https://github.com/srl-labs/srl-acl-lab\n[codespaces-svg]: https://gitlab.com/rdodin/pics/-/wikis/uploads/80546a8c7cda8bb14aa799d26f55bd83/run-codespaces-btn.svg\n[codespaces-url]: https://codespaces.new/srl-labs/srl-acl-lab?quickstart=1\u0026devcontainer_path=.devcontainer%2Fdocker-in-docker%2Fdevcontainer.json\n[w212]: https://gitlab.com/rdodin/pics/-/wikis/uploads/718a32dfa2b375cb07bcac50ae32964a/w212h1.svg\n[w90]: https://gitlab.com/rdodin/pics/-/wikis/uploads/bf1b8ea28b4528eb1b66567355a13c5c/w90h1.svg\n\nGet to know ACLs on SR Linux!\n\nAfter lab is started the following ping should succeed, as there is no default ACL in place.\n\n```bash\nsudo docker exec -i -t acl-client ping -w 2 -c 2 192.168.20.100\n```\n\nThen configure the ACL on ethernet-1/1.0 subinterface of SR Linux to drop ICMP packets destined towards the server:\n\n```bash\ncat icmp_drop.cfg | docker exec -i acl-srl sr_cli -e -c\n```\n\nRepeat the ping, it should not succeed, as the ICMP drop ACL is in place. You can check the logs on SR Linux to ensure that the packets are being dropped:\n\n```bash\nsudo docker exec acl-srl sr_cli show system logging file acl_log\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsrl-labs%2Fsrl-acl-lab","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsrl-labs%2Fsrl-acl-lab","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsrl-labs%2Fsrl-acl-lab/lists"}