02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IP Access Control Lists<br />

In <strong>the</strong> <strong>Force10</strong> switch/routers, you can create two different types of IP ACLs: standard or extended. A<br />

standard ACL filters packets based on <strong>the</strong> source IP packet. An extended ACL filters traffic based on <strong>the</strong><br />

following criteria (<strong>for</strong> more in<strong>for</strong>mation on ACL supported options see <strong>the</strong> <strong>FTOS</strong> Command Reference):<br />

• IP protocol number<br />

• Source IP address<br />

• Destination IP address<br />

• Source TCP port number<br />

• Destination TCP port number<br />

• Source UDP port number<br />

• Destination UDP port number<br />

For extended ACL TCP and UDP filters, you can match criteria on specific or ranges of TCP or UDP<br />

ports. For extended ACL TCP filters, you can also match criteria on established TCP sessions.<br />

When creating an access list, <strong>the</strong> sequence of <strong>the</strong> filters is important. You have a choice of assigning<br />

sequence numbers to <strong>the</strong> filters as you enter <strong>the</strong>m, or <strong>FTOS</strong> will assign numbers in <strong>the</strong> order <strong>the</strong> filters are<br />

created. The sequence numbers, whe<strong>the</strong>r configured or assigned by <strong>FTOS</strong>, are listed in <strong>the</strong> show config<br />

and show ip accounting access-list command display output.<br />

Ingress and egress Hot Lock ACLs allow you to append or delete new rules into an existing ACL (already<br />

written into CAM) without disruption to traffic flow. Existing entries in CAM simply are shuffled to<br />

accommodate new entries. Hot Lock ACLs are enabled by default and support both standard and extended<br />

ACLs.<br />

Hot Lock ACLs are supported on plat<strong>for</strong>m e<br />

Implementation In<strong>for</strong>mation<br />

One IP ACL can be assigned per interface with <strong>FTOS</strong>. If an IP ACL is not assigned to an interface, it is not<br />

used by <strong>the</strong> software in any o<strong>the</strong>r capacity.<br />

The number of entries allowed per ACL is hardware-dependent. Refer to your line card documentation <strong>for</strong><br />

detailed specification on entries allowed per ACL.<br />

If counters are enabled on IP ACL rules that are already configured, those counters are reset when a new<br />

rule is inserted or prepended. If a rule is appended, <strong>the</strong> existing counters are not affected. This is applicable<br />

to <strong>the</strong> following features:<br />

• L2 Ingress Access list<br />

• L2 Egress Access list<br />

334 IP Access Control Lists, Prefix Lists, and Route-maps

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!