Created issue #1 in github <https://github.com/netmod-wg/acl-model/issues/1> as 
“The current model does not support the concept of "containers" or object 
groups used to contain multiple objects per rule entry”.

with a description that says:

Some vendors define the concept of containers or object groups, which is used 
to contain objects such as host names, IP addresses, subnet, range of address, 
protocol, port numbers etc. A single action is then associated with the object 
group, e.g. permit, deny and/or log. This concept is not supported in the model 
currently.

Is this concept important to implement in the model? If so, feature statements 
and identities used in the model to allow vendors to define what they support, 
cannot be extended to such object groups.


Mahesh Jethanandani
mjethanand...@gmail.com



_______________________________________________
netmod mailing list
netmod@ietf.org
https://www.ietf.org/mailman/listinfo/netmod

Reply via email to