Ipspace iconIpspaceSep 28, 2026 ~3 min source read

Prefix Sets: Simplifying netlab ACLs and Prefix Filters

netlab replaced repetitive per-prefix YAML with a generic prefix-set mechanism (release 25.09) that accepts literal prefixes, address pools, VLANs and other object descriptors, reducing YAML bloat and unifying ACL and prefix-filter definitions.

Prefix Sets: Simplifying netlab ACLs and Prefix Filters

Share this story

Send the public story page.

Useful takeaways from this story.

netlab release 25.09 introduced generic prefix sets to replace earlier single-prefix-per-entry designs, cutting YAML verbosity and allowing VLAN, pool, link and named-prefix references.

Platform output differs: Arista EOS generates separate IPv4/IPv6 prefix-lists, while Cisco IOS XR accepts mixed-family prefix sets and emits a combined prefix-set.

# What changed netlab originally generated prefix filters and ACLs to match device configuration patterns. That led to a strict one-prefix-per-entry rule intended to preserve sequence numbers in device configs. It matched device output but caused a lot of YAML bloat: each matching prefix required several YAML lines.

# What a prefix set is A prefix set is a simple list where each list item is one of:

  • an IPv4 or IPv6 literal address or prefix (for example, 192.0.2.0/24 or 2001:db8::/48),
  • an object descriptor in the form namespace.id (for example pool.lan or vlan.red), where namespace identifies a netlab object type that resolves to one or more prefixes.

# How this simplifies ACLs and prefix filters ACL entries and prefix-filter arguments now accept lists. You can concatenate literal prefixes, pool references, and named prefixes in one place. That reduces repetitive YAML and keeps your policy definitions compact.

  • protocol: ip

src.prefix: [ pool.lan, pool.loopback ]

On Arista EOS this produces two ACL entries (IPv4 shown):

# How prefix filters look now The same prefix-set mechanism applies to prefix filters. Each prefix-specifying argument can be a list and the prefix argument can directly name a prefix set.

Example lab snippet using a dual-stack loopback pool, a named prefix, and a literal IPv6 prefix:

addressing.loopback.ipv6: 2001:db8::/48

  • prefix: [ pool.loopback, prefix.alpha, 2001:db8:cafe:2::/64 ]

Based on that, netlab generates these items on Arista EOS:

ip prefix-list example-ipv4 seq 100 permit 10.0.0.0/24 ip prefix-list example-ipv4 seq 110 permit 192.168.42.0/24

ipv6 prefix-list example-ipv6 seq 100 permit 2001:db8::/48 seq 110 permit 2001:db8:cafe:2::/64

Cisco IOS XR accepts mixed-family prefixes in one set. For the same topology netlab emits a combined prefix-set entry like:

10.0.0.0/24, 192.168.42.0/24, 2001:db8::/48, 2001:db8:cafe:2::/64

# Migration notes and compatibility

# Practical effect for users You can write shorter, clearer YAML that references pools, VLANs, link prefixes, and named prefixes. The same prefix set expression can feed both ACLs and prefix filters. Expect platform-specific differences in generated device output: some platforms split IPv4/IPv6 into separate lists, others accept a single mixed-family set.

# Bottom line Prefix sets replace repetitive per-prefix YAML with a flexible list model that accepts literals and object references. The change reduces verbosity, centralizes prefix definitions, and aligns ACL/prefix-filter configuration across netlab features.

More context around this story.

Using Syslog in netlab Labs
Ipspace iconIpspaceSep 24, 2026

Using Syslog in netlab Labs

<p><em>netlab</em> <a href="https://netlab.tools/release/26.09/">release 26.09</a> added support for Syslog clients and servers. We implemented the clients on <a href="https://netlab.tools/module/services/#platform-support">numerous platforms</a>; the only Syslog</p>

netlab 26.09: Syslog, More DNS, Netmiko
Ipspace iconIpspaceSep 21, 2026

netlab 26.09: Syslog, More DNS, Netmiko

<p><em>netlab</em> release 26.09 brings more <em>network services</em> goodies:</p> The <a href="https://netlab.tools/module/services/#module-services"><strong>services</strong> module</a> supports <a href="https://netlab.tools/module/services/#services-syslog-parameters">Syslog clients and servers</a>. DNS and Syslog

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app