Ingress policing provides the ability to monitor the data rates for a particular class of traffic and perform action when traffic exceeds user-configured values. This allows users to control ingress bandwidth based on packet classification.  Ingress policing is done by a policing meter which marks incoming traffic and performs actions based on the results of policing meters. 

This feature allows users to change the scale of IPV6 and MAC subinterface ACLs by changing the port qualifier size (range used for ACL label allocation) through the tcam profile. Increasing the port qualifier size increases the ACL label range, thus allowing more number of ACLs vice versa.

An IPsec service ACL provides a way to block IPsec connections to/from specific addresses. This feature works in a similar way to other protocols in EOS that provide this functionality.

Explicit Congestion Notification (ECN) is an IP and TCP extension that facilitates end to end network congestion

Static NAT rules may optionally include an access list to filter the packets to be translated.