Usage Information To stop packets from flooding the user terminal when debugging is turned on, use the
count
option.
The
access-group
option supports only the equal to (
eq
) operator in TCP ACL rules.
Port operators not equal to (
neq
), greater than (
gt
), less than (
lt
), or
range
are not
supported in access-group option (refer to the following example). ARP packets (
arp
)
and Ether-type (
ether-type
) are also not supported in the
access-group
option.
The entire rule is skipped to compose the filter.
The
access-group
option pertains to:
• IP protocol number: from 0 to 255
• Internet control message protocol (
icmp
) but not the ICMP message type (from 0
to 255)
• Any internet protocol (
ip
)
• Transmission Control Protocol (
tcp
) but not on the
rst
,
syn
, or
urg
bits
• User Datagram Protocol (
udp
)
If an ambiguous access control list rules, the
debug ip packet access-control
command is disabled. A message appears identifying the error (refer to the following
Example).
Example (Error
Messages)
Dell#debug ip packet access-group test
%Error: port operator GT not supported in access-list debug
%Error: port operator LT not supported in access-list debug
%Error: port operator RANGE not supported in access-list debug
%Error: port operator NEQ not supported in access-list debug
Dell#00:10:45: %RPM0-P:CP
%IPMGR-3-DEBUG_IP_PACKET_ACL_AMBIGUOUS_EXP: Ambiguous rules not
supported in access-list debug, access-list debugging is turned
off
Dell#
deny arp (for Extended MAC ACLs)
Configure an egress filter that drops ARP packets on egress ACL supported line cards. (For more information,
refer to your line card documentation).
C9000 Series
Syntax
deny arp {
destination-mac-address mac-address-mask
| any} vlan
vlan-id
{
ip-address
| any | opcode code-
number
} [count [byte]]
[order] [log [interval
minutes
] [threshold-in-msgs [count]]
[monitor]
IPv4 Routing
1185
Summary of Contents for C9000 series
Page 1: ...Dell Networking Command Line Reference Guide for the C9000 Series Version 9 10 0 0 ...
Page 394: ...deny 14551 666 Dell Access Control Lists ACL 394 ...
Page 877: ...algorithm FIPS Cryptography 877 ...
Page 1297: ...Total 5 0 Total 5 active route s using 952 bytes IPv6 Basics 1297 ...