02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

When creating a trace list, <strong>the</strong> sequence of <strong>the</strong> filters is important. You have a choice of assigning sequence<br />

numbers to <strong>the</strong> filters as you enter <strong>the</strong>m, or <strong>FTOS</strong> assigns numbers in <strong>the</strong> order <strong>the</strong> filters were created. For<br />

more in<strong>for</strong>mation on sequence numbering, refer to Chapter 17, IP Access Control Lists, Prefix Lists, and<br />

Route-maps, on page 333.<br />

<strong>Configuration</strong> Task List <strong>for</strong> Trace lists<br />

The following configuration steps include mandatory and optional steps.<br />

• Creating a trace list on page 168 (mandatory)<br />

• Applying trace lists on page 172 (mandatory)<br />

For a complete listing of all commands related to trace lists, refer to <strong>the</strong> Security chapter in <strong>the</strong> <strong>FTOS</strong><br />

Command Reference.<br />

Creating a trace list<br />

Trace lists filter and log traffic based on source and destination IP addresses, IP host addresses, TCP<br />

addresses, TCP host addresses, UDP addresses, and UDP host addresses. When configuring <strong>the</strong> Trace list<br />

filters, include <strong>the</strong> count and bytes parameters so that any hits to that filter are logged.<br />

Since traffic passes through <strong>the</strong> filter in <strong>the</strong> order of <strong>the</strong> filter’s sequence, you can configure <strong>the</strong> trace list by<br />

first entering <strong>the</strong> TRACE LIST mode and <strong>the</strong>n assigning a sequence number to <strong>the</strong> filter.<br />

To create a filter <strong>for</strong> packets with a specified sequence number, use <strong>the</strong>se commands in <strong>the</strong> following<br />

sequence, starting in <strong>the</strong> CONFIGURATION mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 ip trace-list trace-list-name CONFIGURATION Enter <strong>the</strong> TRACE LIST mode by<br />

creating an trace list.<br />

168 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!