Grants, not network ACLs
Authorization in Ixiea is session-scoped. A grant binds an identity (or group) to a target asset, optional account mapping, allowed protocols, and optional time window. Network firewalls may still exist, but the meaningful decision happens at the gateway: without a valid grant, the connection never starts.
Network ACL
Subnet reachability only
Session grant
Identity + target + protocol + window
No grant → connection never starts