For extended ACL, TCP, and UDP filters, you can match criteria on specific or ranges of TCP or UDP ports. For
extended ACL TCP filters, you can also match criteria on established TCP sessions.
When creating an access list, the sequence of the filters is important. You have a choice of assigning
sequence numbers to the filters as you enter them, or the Dell Networking Operating System (OS) assigns
numbers in the order the filters are created. The sequence numbers are listed in the display output of the
show config
and
show ip accounting access-list
commands.
Ingress and egress Hot Lock ACLs allow you to append or delete new rules into an existing ACL (already
written into CAM) without disrupting traffic flow. Existing entries in the CAM are shuffled to accommodate the
new entries. Hot lock ACLs are enabled by default and support both standard and extended ACLs and on all
platforms.
NOTE:
Hot lock ACLs are supported for Ingress ACLs only.
CAM Usage
The following section describes CAM allocation and CAM optimization.
•
User Configurable CAM Allocation
•
User Configurable CAM Allocation
Allocate space for IPV6 ACLs by using the
cam-acl
command in CONFIGURATION mode.
The CAM space is allotted in filter processor (FP) blocks. The total space allocated must equal 13 FP blocks.
(There are 16 FP blocks, but System Flow requires three blocks that cannot be reallocated.)
Enter the
ipv6acl
allocation as a factor of 2 (2, 4, 6, 8, 10). All other profile allocations can use either even or
odd numbered ranges.
If you want to configure ACL's on VRF instances, you must allocate a CAM region using the
vrfv4acl
option in
the cam-acl command.
Save the new CAM settings to the startup-config (use
write-mem
or
copy run start
) then reload the
system for the new settings to take effect.
CAM Optimization
When you enable this command, if a policy map containing classification rules (ACL and/or dscp/ ip-
precedence rules) is applied to more than one physical interface on the same port-pipe, only a single copy of
the policy is written (only one FP entry is used). When you disable this command, the system behaves as
described in this chapter.
Access Control Lists (ACLs)
139
Содержание S4048T
Страница 1: ...Dell Configuration Guide for the S4048T ON System 9 10 0 1 ...
Страница 98: ... saveenv 7 Reload the system uBoot mode reset Management 98 ...
Страница 113: ...Total CFM Pkts 10303 CCM Pkts 0 LBM Pkts 0 LTM Pkts 3 LBR Pkts 0 LTR Pkts 0 802 1ag 113 ...
Страница 411: ...mode transit no disable Force10 Resilient Ring Protocol FRRP 411 ...
Страница 590: ...Figure 67 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 590 ...
Страница 591: ...Figure 68 Inspecting Configuration of LAG 10 on ALPHA Link Aggregation Control Protocol LACP 591 ...
Страница 594: ...Figure 70 Inspecting a LAG Port on BRAVO Using the show interface Command Link Aggregation Control Protocol LACP 594 ...
Страница 595: ...Figure 71 Inspecting LAG 10 Using the show interfaces port channel Command Link Aggregation Control Protocol LACP 595 ...
Страница 646: ...Figure 87 Configuring Interfaces for MSDP Multicast Source Discovery Protocol MSDP 646 ...
Страница 647: ...Figure 88 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 647 ...
Страница 648: ...Figure 89 Configuring PIM in Multiple Routing Domains Multicast Source Discovery Protocol MSDP 648 ...
Страница 653: ...Figure 91 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 653 ...
Страница 654: ...Figure 92 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 654 ...
Страница 955: ...Figure 119 Single and Double Tag First byte TPID Match Service Provider Bridging 955 ...
Страница 1179: ...Figure 147 Create Hypervisor Figure 148 Edit Hypervisor Figure 149 Create Transport Connector Virtual Extensible LAN VXLAN 1179 ...