![Dell S6000-ON Скачать руководство пользователя страница 113](http://html.mh-extra.com/html/dell/s6000-on/s6000-on_configuration-manual_84557113.webp)
Assign an IP ACL to an Interface
To pass traffic through a configured IP ACL, assign that ACL to a physical interface, a port channel
interface, or a VLAN.
The IP ACL is applied to all traffic entering a physical or port channel interface and the traffic is either
forwarded or dropped depending on the criteria and actions specified in the ACL.
The same ACL may be applied to different interfaces and that changes its functionality. For example, you
can take ACL “ABCD” and apply it using the
in
keyword and it becomes an ingress access list. If you apply
the same ACL using the
out
keyword, it becomes an egress access list. If you apply the same ACL to the
Loopback interface, it becomes a Loopback access list.
This section describes the following:
•
Configure Ingress ACLs
•
Configure Egress ACLs
For more information about Layer-3 interfaces, refer to
Interfaces
.
Applying an IP ACL
To apply an IP ACL (standard or extended) to a physical or port channel interface, use the following
commands.
1.
Enter the interface number.
CONFIGURATION mode
interface interface
slot/port
2.
Configure an IP address for the interface, placing it in Layer-3 mode.
INTERFACE mode
ip address
ip-address
3.
Apply an IP ACL to traffic entering or exiting an interface.
INTERFACE mode
ip access-group
access-list-name
{in} [implicit-permit] [vlan
vlan-range
|
vrf vrf-range]
NOTE: The number of entries allowed per ACL is hardware-dependent. For detailed
specification about entries allowed per ACL, refer to your line card documentation.
4.
Apply rules to the new ACL.
INTERFACE mode
ip access-list [standard | extended]
name
To view which IP ACL is applied to an interface, use the
show config
command in INTERFACE mode, or
use the
show running-config
command in EXEC mode.
Example of Viewing ACLs Applied to an Interface
Dell(conf-if)#show conf
!
interface TenGigabitEthernet 1/1/1
Access Control Lists (ACLs)
113
Содержание S6000-ON
Страница 1: ...Dell Configuration Guide for the S6000 ON System 9 9 0 0 ...
Страница 505: ...Figure 60 Inspecting Configuration of LAG 10 on ALPHA Link Aggregation Control Protocol LACP 505 ...
Страница 508: ...Figure 62 Inspecting a LAG Port on BRAVO Using the show interface Command 508 Link Aggregation Control Protocol LACP ...
Страница 509: ...Figure 63 Inspecting LAG 10 Using the show interfaces port channel Command Link Aggregation Control Protocol LACP 509 ...
Страница 552: ...mac address table static multicast mac address vlan vlan id output range interface 552 Microsoft Network Load Balancing ...
Страница 557: ...Figure 80 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 557 ...
Страница 558: ...Figure 81 Configuring PIM in Multiple Routing Domains 558 Multicast Source Discovery Protocol MSDP ...
Страница 562: ...Figure 83 MSDP Default Peer Scenario 1 562 Multicast Source Discovery Protocol MSDP ...
Страница 563: ...Figure 84 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 563 ...
Страница 564: ...Figure 85 MSDP Default Peer Scenario 3 564 Multicast Source Discovery Protocol MSDP ...
Страница 665: ...Policy based Routing PBR 665 ...
Страница 672: ...ip pim bsr border Remove candidate RP advertisements clear ip pim rp mapping 672 PIM Sparse Mode PIM SM ...
Страница 818: ...Figure 110 Single and Double Tag TPID Match 818 Service Provider Bridging ...
Страница 819: ...Figure 111 Single and Double Tag First byte TPID Match Service Provider Bridging 819 ...
Страница 995: ...Figure 140 Setup OSPF and Static Routes Virtual Routing and Forwarding VRF 995 ...