By default, 10 ACL logs are generated if you do not specify the threshold explicitly.
The default frequency at which ACL logs are generated is five minutes. By default,
flow-based monitoring is not enabled.
Use the
monitor
option only when you are using flow-based monitoring. For
more information, refer to the Port Monitoring chapter of the
Z9500 Configuration
Guide
.
Related
Commands
deny
— configures a filter to drop packets.
permit
— configures a filter to forward packets.
Extended IP ACL Commands
When an ACL is created without any rule and then applied to an interface, ACL behavior reflects an
implicit permit.
The following commands configure extended IP ACLs, which in addition to the IP address, also examine
the packet’s protocol type.
The Z9500 supports both Ingress and Egress IP ACLs.
NOTE: Also refer to the
Commands Common to all ACL Types
and
Common IP ACL Commands
sections.
deny
Configure a filter that drops IP packets meeting the filter criteria.
Z9500
Syntax
deny {ip |
ip-protocol-number
} {
source mask
| any | host
ip-
address
} {
destination
mask | any | host
ip-address
} [count
[bytes]] [dscp
value
] [order] [monitor] [fragments] [log
[interval
minutes
] [threshold-in-msgs [count]] [monitor]
To remove this filter, you have two choices:
• Use the
no seq
sequence-number
command if you know the filter’s
sequence number.
• Use the
no deny {ip |
ip-protocol-number
} {
source mask
| any |
host
ip-address
} {
destination mask
| any | host
ip-address
}
command.
Parameters
ip
Enter the keyword
ip
to configure a generic IP access list.
The keyword
ip
specifies that the access list denies all IP
protocols.
Access Control Lists (ACL)
233