02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Step Command Syntax Command Mode Purpose<br />

2<br />

seq sequence-number {deny |<br />

permit} {ip-protocol-number |<br />

icmp | ip | tcp | udp}<br />

{source mask | any | host<br />

ip-address} {destination mask |<br />

any | host ip-address}<br />

[operator port [port]] [count<br />

[byte] | log ] [order] [monitor]<br />

CONFIG-EXT-NACL Configure a drop or <strong>for</strong>ward filter.<br />

• log and monitor options are<br />

supported on E-<strong>Series</strong> only.<br />

When you use <strong>the</strong> ‘log’ option, CP processor logs details about <strong>the</strong> packets that match. Depending on how<br />

many packets match <strong>the</strong> ‘log’ entry and at what rate, <strong>the</strong> CP may become busy as it has to log <strong>the</strong>se<br />

packets’ details.<br />

To create a filter <strong>for</strong> TCP packets with a specified sequence number, use <strong>the</strong>se commands in <strong>the</strong> following<br />

sequence, starting in <strong>the</strong> CONFIGURATION mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 ip access-list extended<br />

access-list-name<br />

2<br />

seq sequence-number {deny<br />

| permit} tcp {source mask |<br />

any | host ip-address}}<br />

[count [byte] | log ] [order]<br />

[monitor]<br />

CONFIGURATION Create an extended IP ACL and assign it a<br />

unique name.<br />

CONFIG-EXT-NACL Configure an extended IP ACL filter <strong>for</strong> TCP<br />

packets.<br />

• log and monitor options are supported<br />

on E-<strong>Series</strong> only.<br />

When you use <strong>the</strong> ‘log’ option, CP processor logs details about <strong>the</strong> packets that match. Depending on how<br />

many packets match <strong>the</strong> ‘log’ entry and at what rate, <strong>the</strong> CP may become busy as it has to log <strong>the</strong>se<br />

packets’ details.<br />

To create a filter <strong>for</strong> UDP packets with a specified sequence number, use <strong>the</strong>se commands in <strong>the</strong> following<br />

sequence, starting in <strong>the</strong> CONFIGURATION mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 ip access-list extended<br />

access-list-name<br />

CONFIGURATION Create a extended IP ACL and assign it a<br />

unique name.<br />

340 IP Access Control Lists, Prefix Lists, and Route-maps

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!