02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Command Syntax Command Mode Purpose<br />

{deny | permit} udp {source mask | any | host<br />

ip-address} [operator port [port]] {destination<br />

mask | any | host ip-address} [operator port<br />

[port]] | log]<br />

Figure 84 illustrates a Trace list in which <strong>the</strong> sequence numbers were assigned by <strong>the</strong> software. The filters<br />

were assigned sequence numbers based on <strong>the</strong> order in which <strong>the</strong>y were configured (<strong>for</strong> example, <strong>the</strong> first<br />

filter was given <strong>the</strong> lowest sequence number). The show config command in <strong>the</strong> TRACE LIST mode<br />

displays <strong>the</strong> two filters with <strong>the</strong> sequence numbers 5 and 10.<br />

Figure 84 Trace list Example<br />

To view all configured Trace lists and <strong>the</strong> number of packets processed through <strong>the</strong> Trace list, use <strong>the</strong> show<br />

ip accounting trace-list command (Figure 83) in <strong>the</strong> EXEC privilege mode.<br />

Applying trace lists<br />

After you create a Trace list, you must enable it. Without enabling <strong>the</strong> Trace list, no traffic is filtered.<br />

You can enable one Trace list.<br />

TRACE LIST Configure a deny or permit filter to<br />

examine UDP packets. Configure <strong>the</strong><br />

following required and optional<br />

parameters:<br />

• source: An IP address as <strong>the</strong><br />

source IP address <strong>for</strong> <strong>the</strong> filter to<br />

match.<br />

• mask: a network mask<br />

• any: to match any IP source<br />

address<br />

• host ip-address: to match IP<br />

addresses in a host.<br />

• destination: An IP address as <strong>the</strong><br />

source IP address <strong>for</strong> <strong>the</strong> filter to<br />

match.<br />

• precedence precedence range: 0 to<br />

7.<br />

• tos tos-value range: 0 to 15<br />

• count: count packets processed by<br />

<strong>the</strong> filter.<br />

• byte: count bytes processed by <strong>the</strong><br />

filter.<br />

• log: is supported.<br />

<strong>Force10</strong>(config-trace-acl)#deny tcp host 123.55.34.0 any<br />

<strong>Force10</strong>(config-trace-acl)#permit udp 154.44.123.34 0.0.255.255 host 34.6.0.0<br />

<strong>Force10</strong>(config-trace-acl)#show config<br />

!<br />

ip trace-list nimule<br />

seq 5 deny tcp host 123.55.34.0 any<br />

seq 10 permit udp 154.44.0.0 0.0.255.255 host 34.6.0.0<br />

172 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!