The MAC ACL supports an inverse mask; therefore, a mask of
ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of
00:00:00:00:00:00 only allows entries that match exactly.
any
Enter the keyword
any
to match and drop specific Ethernet traffic on
the interface.
vlan
vlan-id
Enter the keyword
vlan
and then enter the VLAN ID to filter traffic
associated with a specific VLAN. The range is 1 to 4094 and 1 to 2094
for ExaScale (you can use IDs 1 to 4094). To filter all VLAN traffic,
specify
VLAN 1
.
ip-address
Enter an IP address in dotted decimal format (A.B.C.D) as the target
IP address of the ARP.
opcode
code-
number
Enter the keyword
opcode
followed by the number of the ARP
opcode. The range is 1 to 16.
count
(OPTIONAL) Enter the keyword
count
to count packets processed
by the filter.
byte
(OPTIONAL) Enter the keyword
byte
to count bytes processed by
the filter.
log
(OPTIONAL, E-Series only) Enter the keyword
log
to have the
information kept in an ACL log file.
order
(OPTIONAL) Enter the keyword
order
to specify the QoS priority for
the ACL entry. The range is 0 to 254 (where 0 is the highest priority
and 254 is the lowest; lower order numbers have a higher priority). If
you do not use the keyword
order
, the ACLs have the lowest order
by default (255).
monitor
(OPTIONAL) Enter the keyword
monitor
when the rule is describing
the traffic that you want to monitor and the ACL in which you are
creating the rule is applied to the monitored interface.
NOTE: For more information, refer to the Flow-based Monitoring
section in the Port Monitoring chapter of the
FTOS Configuration
Guide
.
fragments
Enter the keyword
fragments
to use ACLs to control packet
fragments.
Defaults
Not configured.
Command Modes
CONFIGURATION-EXTENDED-ACCESS-LIST
Command History
Version 8.2.1.0
Allows ACL control of fragmented packets for IP (Layer 3) ACLs.
Version 8.1.1.0
Introduced on the E-Series ExaScale.
Version 7.4.1.0
Added the
monitor
option.
Version 6.5.10
Expanded to include the optional QoS
order
priority for the ACL
entry.
244
Summary of Contents for Force10 Z9000
Page 1: ...FTOS Command Line Reference Guide for the Z9000 System FTOS 9 1 0 0 ...
Page 96: ...96 ...
Page 194: ...194 ...
Page 312: ...312 ...
Page 540: ...540 ...
Page 546: ...546 ...
Page 560: ...560 ...
Page 566: ...566 ...
Page 590: ...action act UpdateCounter param0 1 0x01 param1 0 0x00 output truncated 590 ...
Page 624: ...624 ...
Page 638: ...638 ...
Page 648: ...648 ...
Page 659: ...Related Commands show gvrp displays the GVRP configuration 659 ...
Page 660: ...660 ...
Page 834: ...834 ...
Page 854: ...854 ...
Page 906: ...906 ...
Page 914: ...914 ...
Page 976: ...976 ...
Page 990: ...990 ...
Page 1006: ...1006 ...
Page 1008: ...1008 ...
Page 1026: ...1026 ...
Page 1145: ...10 211 1 2 Outgoing interface list GigabitEthernet 8 0 1145 ...
Page 1146: ...1146 ...
Page 1156: ...1156 ...
Page 1166: ...1166 ...
Page 1180: ...1180 ...
Page 1258: ...1258 ...
Page 1272: ...1272 ...
Page 1394: ...1394 ...
Page 1400: ...1400 ...
Page 1410: ...1410 ...
Page 1424: ...1424 ...
Page 1444: ...1444 ...
Page 1468: ...Version 8 3 8 0 Introduced on the S4810 1468 ...
Page 1470: ...1470 ...