02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

To view which IP ACL is applied to an interface, use <strong>the</strong> show config command (Figure 232) in <strong>the</strong><br />

INTERFACE mode or <strong>the</strong> show running-config command in <strong>the</strong> EXEC mode.<br />

Figure 232 Show config Command in <strong>the</strong> INTERFACE Mode<br />

Use only Standard ACLs in <strong>the</strong> access-class command to filter traffic on Telnet sessions.<br />

Counting ACL Hits<br />

You can view <strong>the</strong> number of packets matching <strong>the</strong> ACL by using <strong>the</strong> count option when creating ACL<br />

entries. E-<strong>Series</strong> supports packet and byte counts simultaneously. C-<strong>Series</strong> supports only one at any given<br />

time.<br />

To view <strong>the</strong> number of packets matching an ACL that is applied to an interface:<br />

Step Task<br />

<strong>Force10</strong>(conf-if)#show conf<br />

!<br />

interface GigabitE<strong>the</strong>rnet 0/0<br />

ip address 10.2.1.100 255.255.255.0<br />

ip access-group nimule in<br />

no shutdown<br />

<strong>Force10</strong>(conf-if)#<br />

1 Create an ACL that uses rules with <strong>the</strong> count option. See Configuring IP ACLs on page 337<br />

2 Apply <strong>the</strong> ACL as an inbound or outbound ACL on an interface. See Assign an IP ACL to an Interface<br />

on page 343<br />

3 View <strong>the</strong> number of packets matching <strong>the</strong> ACL using <strong>the</strong> show ip accounting access-list from<br />

EXEC Privilege mode.<br />

Configuring Ingress ACLs<br />

Ingress ACLs are applied to interfaces and to traffic entering <strong>the</strong> system.These system-wide ACLs<br />

eliminate <strong>the</strong> need to apply ACLs onto each interface and achieves <strong>the</strong> same results. By localizing target<br />

traffic, it is a simpler implementation.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 345

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!