02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

To pass traffic through a configured IP ACL, you must assign that ACL to a physical interface, a port<br />

channel interface, or a VLAN. The IP ACL is applied to all traffic entering a physical or port channel<br />

interface and <strong>the</strong> traffic is ei<strong>the</strong>r <strong>for</strong>warded or dropped depending on <strong>the</strong> criteria and actions specified in<br />

<strong>the</strong> ACL.<br />

The same ACL may be applied to different interfaces and that changes its functionality. For example, you<br />

can take ACL "ABCD", and apply it using <strong>the</strong> in keyword and it becomes an ingress access list. If you<br />

apply <strong>the</strong> same ACL using <strong>the</strong> out keyword, it becomes an egress access list. If you apply <strong>the</strong> same ACL<br />

to <strong>the</strong> loopback interface, it becomes a loopback access list.<br />

This chapter covers <strong>the</strong> following topics:<br />

• Configuring Ingress ACLs on page 345<br />

• Configuring Egress ACLs on page 346<br />

• Configuring ACLs to Loopback on page 348<br />

For more in<strong>for</strong>mation on Layer-3 interfaces, refer to Chapter 13, Interfaces, on page 245.<br />

To apply an IP ACL (standard or extended) to a physical or port channel interface, use <strong>the</strong>se commands in<br />

<strong>the</strong> following sequence in <strong>the</strong> INTERFACE mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 interface interface slot/port CONFIGURATION Enter <strong>the</strong> interface number.<br />

2 ip address ip-address INTERFACE Configure an IP address <strong>for</strong> <strong>the</strong> interface,<br />

placing it in Layer-3 mode.<br />

3<br />

4<br />

ip access-group<br />

access-list-name {in | out}<br />

[implicit-permit] [vlan<br />

vlan-range]<br />

ip access-list [standard |<br />

extended] name<br />

INTERFACE Apply an IP ACL to traffic entering or exiting<br />

an interface.<br />

• out: configure <strong>the</strong> ACL to filter outgoing<br />

traffic. This keyword is supported only on<br />

E-<strong>Series</strong>.<br />

Note: The number of entries allowed per<br />

ACL is hardware-dependent. Refer to<br />

your line card documentation <strong>for</strong> detailed<br />

specification on entries allowed per ACL.<br />

INTERFACE Apply rules to <strong>the</strong> new ACL.<br />

344 IP Access Control Lists, Prefix Lists, and Route-maps

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!