02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 17<br />

IP Access Control Lists, Prefix Lists, and Route-maps are supported on plat<strong>for</strong>ms: c e s<br />

Ingress IP ACLs are supported on plat<strong>for</strong>ms: c s<br />

Ingress and Egress IP ACLs are supported on plat<strong>for</strong>m: e<br />

Overview<br />

At <strong>the</strong>ir simplest, Access Control Lists (ACLs), Prefix lists, and Route-maps permit or deny traffic based<br />

on MAC and/or IP addresses. This chapter discusses implementing IP ACLs, IP Prefix lists and<br />

Route-maps. For MAC ACLS, refer to Chapter 9, Layer 2, on page 181.<br />

An ACL is essentially a filter containing some criteria to match (examine IP, TCP, or UDP packets) and an<br />

action to take (permit or deny). ACLs are processed in sequence so that if a packet does not match <strong>the</strong><br />

criterion in <strong>the</strong> first filter, <strong>the</strong> second filter (if configured) is applied. When a packet matches a filter, <strong>the</strong><br />

switch drops or <strong>for</strong>wards <strong>the</strong> packet based on <strong>the</strong> filter’s specified action. If <strong>the</strong> packet does not match any<br />

of <strong>the</strong> filters in <strong>the</strong> ACL, <strong>the</strong> packet is dropped ( implicit deny).<br />

The number of ACLs supported on a system depends on your CAM size. Refer toChapter 3, Content<br />

Addressable Memory (CAM), on page 77 <strong>for</strong> complete CAM profiling in<strong>for</strong>mation.<br />

This chapter covers <strong>the</strong> following topics:<br />

• IP Access Control Lists on page 334<br />

— Configuring Layer 2 and Layer 3 ACLs on an Interface on page 343<br />

— Assign an IP ACL to an Interface on page 343<br />

— Configuring Ingress ACLs on page 345<br />

— Configuring Egress ACLs on page 346<br />

— Configuring ACLs to Loopback on page 348<br />

— Applying an ACL on Loopback Interfaces on page 348<br />

• IP Prefix Lists on page 349<br />

• ACL Resequencing on page 355<br />

• Route Maps on page 357<br />

IP Access Control Lists,<br />

Prefix Lists, and Route-maps<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 333

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!