ACL rules with SSR tenant or service


lab setup

block the sourceping 10.100.12.3 routing-instance vr-11 source 10.100.11.2
block the destionation

ping 10.100.12.3 routing-instance vr-11 source 10.100.11.3


ACL based on destinationcreate a new service

ping 10.100.12.3 routing-instance vr-11 source 10.100.11.2


"clone the current service "

Change the dest to a single /32


change to deny
ACL based on destinationcreate a new child-service
name=  drop.xxxxxxxxxxxx


select only one /32 

Drop / deny this customer1



ACL based on sourcetenant and access-policy in Services based on IP address



ping 10.100.12.3 routing-instance vr-11 source 10.100.11.3


create an access list