102
|
Access Control Lists (ACL)
www.dell.com | support.dell.com
Extended IP ACL Commands
When an ACL is created without any rule and then applied to an interface, ACL behavior reflects an
implicit permit.
The following commands configure extended IP ACLs, which in addition to the IP address also
examine the packet’s protocol type.
The MXL 10/40GbE Switch IO Module platform supports both ingress and egress IP ACLs.
•
deny
•
deny icmp
•
deny tcp
•
deny udp
•
ip access-list extended
•
permit
•
permit icmp
•
permit tcp
•
permit udp
•
seq
deny
Configure a filter that drops IP packets meeting the filter criteria.
Syntax
deny
{
ip |
ip-protocol-number
}
{
source mask
|
any
|
host
ip-address
} {
destination mask
|
any
|
host
ip-address
} [
count
[
byte
]] [
dscp
value
] [
order
] [
fragments
]
To remove this filter, you have two choices:
•
Use the
no
seq
sequence-number
command if you know the filter’s sequence number.
•
Use the
no
deny
{
ip |
ip-protocol-number
}
{
source mask
|
any
|
host
ip-address
} {
destination
mask
|
any
|
host
ip-address
} command.
Parameters
Note:
See also
Commands Common to all ACL Types
and
Common IP ACL Commands
.
ip
Enter the keyword
ip
to configure a generic IP access list. The keyword
ip
specifies that the access list will deny all IP protocols.
ip-protocol-number
Enter a number from 0 to 255 to deny based on the protocol identified in the IP
protocol header.
source
Enter the IP address of the network or host from which the packets were sent.
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask, when
specified in A.B.C.D format, may be either contiguous or non-contiguous.
any
Enter the keyword
any
to specify that all routes are subject to the filter.
host
ip-address
Enter the keyword
host
followed by the IP address to specify a host IP address.
destination
Enter the IP address of the network or host to which the packets are sent.
count
(OPTIONAL) Enter the keyword
count
to count packets processed by the
filter.
Summary of Contents for Force10 MXL Blade
Page 80: ...80 Control and Monitoring w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 142: ...142 Access Control Lists ACL w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 146: ...146 Bare Metal Provisioning w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 152: ...152 Content Addressable Memory CAM w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 186: ...186 Data Center Bridging w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 204: ...204 Dynamic Host Configuration Protocol DHCP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 216: ...216 FIP Snooping w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 226: ...226 GARP VLAN Registration GVRP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 234: ...234 Internet Group Management Protocol IGMP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 330: ...330 iSCSI Optimization w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 354: ...354 Layer 2 w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 370: ...370 Link Layer Discovery Protocol LLDP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 384: ...384 Multiple Spanning Tree Protocol MSTP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 438: ...438 Port Monitoring w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 448: ...448 Private VLAN PVLAN w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 490: ...490 Quality of Service QoS w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 518: ...518 Remote Monitoring RMON w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 530: ...530 Rapid Spanning Tree Protocol RSTP w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 570: ...570 Security w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 578: ...578 sFlow w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 620: ...620 Stacking Commands w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 654: ...654 Uplink Failure Detection UFD w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 693: ...Debugging and Diagnostics 693 ...
Page 694: ...694 Debugging and Diagnostics w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 712: ...712 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 713: ...Index 713 ...
Page 714: ...714 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 715: ...Index 715 ...
Page 716: ...716 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 717: ...Index 717 ...
Page 718: ...718 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 728: ...728 Command Index w w w d e l l c o m s u p p o r t d e l l c o m write 78 write memory 25 ...
Page 729: ...Command Index 729 ...
Page 730: ...730 Command Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 731: ...Command Index 731 ...
Page 732: ...732 Command Index w w w d e l l c o m s u p p o r t d e l l c o m ...