02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring IP ACLs<br />

To configure an ACL, use commands in <strong>the</strong> IP ACCESS LIST mode and <strong>the</strong> INTERFACE mode. The<br />

following list includes <strong>the</strong> configuration tasks <strong>for</strong> IP ACLs:<br />

• Configure a standard IP ACL on page 337<br />

• Configure an extended IP ACL on page 339<br />

For a complete listing of all commands related to IP ACLs, refer to <strong>the</strong> <strong>FTOS</strong> Command Line Interface<br />

Reference document.<br />

Configure a standard IP ACL<br />

A standard IP ACL uses <strong>the</strong> source IP address as its match criterion.<br />

To configure a standard IP ACL, use <strong>the</strong>se commands in <strong>the</strong> following sequence:<br />

Step Command Syntax Command Mode Purpose<br />

1 ip access-list standard<br />

access-listname<br />

2<br />

seq sequence-number {deny | permit}<br />

{source [mask] | any | host ip-address}<br />

[count [byte] | log ] [order] [monitor]<br />

CONFIGURATION Enter IP ACCESS LIST mode by<br />

naming a standard IP access list.<br />

CONFIG-STD-NACL Configure a drop or <strong>for</strong>ward filter.<br />

The parameters are:<br />

• log and monitor options are<br />

supported on E-<strong>Series</strong> only.<br />

Note: When assigning sequence numbers to filters, keep in mind that you might need to insert a<br />

new filter. To prevent reconfiguring multiple filters, assign sequence numbers in multiples of five or<br />

ano<strong>the</strong>r number.<br />

When you use <strong>the</strong> ‘log’ option, CP processor logs details about <strong>the</strong> packets that match. Depending on how<br />

many packets match <strong>the</strong> ‘log’ entry and at what rate, <strong>the</strong> CP may become busy as it has to log <strong>the</strong>se<br />

packets’ details.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 337

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!