258
ACL Commands
classifier rule. The ACL logging feature allows these hardware hit counts to be
collected on a per-rule basis and reported periodically to the network
administrator using the system logging facility and an SNMP trap.
The Dell Networking ACL permit/deny rule specification supports a
log
parameter that enables hardware hit count collection and reporting.
Depending on platform capabilities, logging can be specified for deny rules,
permit rules, or both. A five minute logging interval is used, at which time
trap log entries are written for each ACL logging rule that accumulated a
nonzero hit count during that interval. The logging interval is not user
configurable.
How to Build ACLs
This section describes how to build ACLs that are less likely to exhibit false
matches.
Administrators are cautioned to specify ACL access-list, permit and deny rule
criteria as fully as is possible in order to avoid false matches. This is especially
true in networks with protocols such as FCoE that have newly introduced
Ether type values. As an example, rules that specify a TCP or UDP port value
should also specify the TCP or UDP protocol and the IPv4 or IPv6 Ether type.
Rules that specify an IP protocol should also specify the Ether type value for
the frame. In general, any rule that specifies matching on an upper layer
protocol field should also include matching constraints for each of the lower
layer protocols. For example, a rule to match packets directed to the well-
known UDP port number 22 (SSH) should also include matching constraints
on the IP protocol field (protocol = 0x11 or UDP) and the Ether type field
(Ether type = 0x0800 or IPv4). In Table 6-1 is a list of commonly used Ether
types and, in Table 6-2 commonly used IP protocol numbers.
2CSNXXX_SWUM200.book Page 258 Tuesday, December 10, 2013 1:22 PM
Summary of Contents for Networking 2048
Page 82: ...Contents 82 ...
Page 216: ...216 Layer 2 Switching Commands ...
Page 248: ...248 AAA Commands ...
Page 256: ...256 Administrative Profiles Commands ...
Page 278: ...278 ACL Commands ...
Page 296: ...296 Address Table Commands ...
Page 344: ...344 DHCP Snooping Commands ...
Page 356: ...356 Dynamic ARP Inspection Commands 12 Enabled Disabled ...
Page 414: ...414 Ethernet Configuration Commands ...
Page 466: ...466 IGMP Snooping Commands ...
Page 476: ...476 IGMP Snooping Querier Commands ...
Page 508: ...508 IPv6 Access List Commands ...
Page 520: ...520 IPv6 MLD Snooping Commands ...
Page 528: ...528 IPv6 MLD Snooping Querier Commands ...
Page 550: ...550 Link Dependency Commands ...
Page 574: ...574 LLDP Commands ...
Page 606: ...606 Port Channel Commands ...
Page 626: ...626 MLAG ...
Page 634: ...634 Port Monitor Commands ...
Page 728: ...728 RADIUS Commands ...
Page 780: ...780 TACACS Commands ...
Page 790: ...790 UDLD Commands User Guidelines This command has no user guidelines ...
Page 840: ...840 Voice VLAN Commands ...
Page 878: ...878 802 1x Commands ...
Page 880: ...880 Data Center Technology Commands ...
Page 915: ...Priority Flow Control Commands 915 Te1 0 23 0 2 4 7 3 Active Te1 0 24 0 7 Inactive ...
Page 916: ...916 Priority Flow Control Commands ...
Page 918: ...918 Layer 3 Commands ...
Page 958: ...958 DHCP Server and Relay Agent Commands ...
Page 994: ...994 DHCPv6 Snooping Commands ...
Page 1002: ...1002 DVMRP Commands ...
Page 1006: ...1006 GMRP Commands ...
Page 1028: ...1028 IGMP Proxy Commands ...
Page 1080: ...1080 IP Routing Commands ...
Page 1131: ...IPv6 Routing Commands 1131 2 2001 2 12 msec 13 msec 12 msec 3 2001 2 14 msec 9 msec 11 msec ...
Page 1132: ...1132 IPv6 Routing Commands ...
Page 1136: ...1136 Loopback Interface Commands ...
Page 1165: ...Multicast Commands 1165 ...
Page 1166: ...1166 Multicast Commands ...
Page 1188: ...1188 IPv6 Multicast Commands ...
Page 1189: ...IPv6 Multicast Commands 1189 ...
Page 1190: ...1190 IPv6 Multicast Commands ...
Page 1276: ...1276 OSPF Commands console config router timers spf 20 30 ...
Page 1356: ...1356 Routing Information Protocol Commands ...
Page 1362: ...1362 Tunnel Interface Commands ...
Page 1384: ...1384 Virtual Router Redundancy Protocol Commands ...
Page 1386: ...1386 Utility Commands ...
Page 1426: ...1426 Captive Portal Commands ...
Page 1450: ...1450 Clock Commands ...
Page 1456: ...1456 Command Line Configuration Scripting Commands ...
Page 1476: ...1476 Configuration and Image File Commands ...
Page 1520: ...1520 Password Management Commands ...
Page 1564: ...1564 SDM Templates Commands ...
Page 1596: ...1596 Serviceability Tracing Packet Commands ...
Page 1608: ...1608 Sflow Commands ...
Page 1634: ...1634 SNMP Commands ...
Page 1668: ...1668 Syslog Commands ...
Page 1744: ...1744 System Management Commands ...
Page 1750: ...1750 Terminal Length Commands ...
Page 1762: ...1762 USB Flash Drive Commands ...
Page 1786: ...1786 Web Server Commands ...
Page 1821: ...W write 1474 write core 1593 ...
Page 1822: ...www dell com support dell com Printed in the U S A ...
Page 1823: ......