18.10.2013 Views

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

permit arp<br />

permit arp<br />

c e s Configure a filter that <strong>for</strong>wards ARP packets meeting this criteria.This command is supported<br />

only on 12-port GE line cards with SFP optics; refer to your line card documentation <strong>for</strong><br />

specifications.<br />

Syntax permit arp {destination-mac-address mac-address-mask | any} vlan vlan-id<br />

{ip-address | any | opcode code-number} [count [byte] | log ] [order] [monitor]<br />

Parameters<br />

To remove this filter, use one of <strong>the</strong> following:<br />

• use <strong>the</strong> no seq sequence-number command syntax if you know <strong>the</strong> filter’s sequence<br />

number or<br />

• use <strong>the</strong> no permit arp {destination-mac-address mac-address-mask | any} vlan<br />

vlan-id {ip-address | any | opcode code-number} command.<br />

destination-mac-address<br />

mac-address-mask<br />

Enter a MAC address and mask in <strong>the</strong> nn:nn:nn:nn:nn <strong>for</strong>mat.<br />

For <strong>the</strong> MAC address mask, specify which bits in <strong>the</strong> MAC address<br />

must match.<br />

The MAC ACL supports an inverse mask, <strong>the</strong>re<strong>for</strong>e, a mask of<br />

ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of<br />

00:00:00:00:00:00 only allows entries that match exactly.<br />

any Enter <strong>the</strong> keyword any to match and drop any ARP traffic on <strong>the</strong><br />

interface.<br />

vlan vlan-id Enter <strong>the</strong> keyword vlan followed by <strong>the</strong> VLAN ID to filter traffic<br />

associated with a specific VLAN.<br />

Range: 1 to 4094<br />

To filter all VLAN traffic specify VLAN 1.<br />

ip-address Enter an IP address in dotted decimal <strong>for</strong>mat (A.B.C.D) as <strong>the</strong> target<br />

IP address of <strong>the</strong> ARP.<br />

opcode code-number Enter <strong>the</strong> keyword opcode followed by <strong>the</strong> number of <strong>the</strong> ARP<br />

opcode.<br />

Range: 1 to 16.<br />

count (OPTIONAL) Enter <strong>the</strong> keyword count to count packets processed<br />

by <strong>the</strong> filter.<br />

byte (OPTIONAL) Enter <strong>the</strong> keyword byte to count bytes processed by<br />

<strong>the</strong> filter.<br />

log (OPTIONAL) Enter <strong>the</strong> keyword log to have <strong>the</strong> in<strong>for</strong>mation kept in<br />

an ACL log file.<br />

order (OPTIONAL) Enter <strong>the</strong> keyword order to specify <strong>the</strong> QoS order of<br />

priority <strong>for</strong> <strong>the</strong> ACL entry.<br />

Range: 0-254 (where 0 is <strong>the</strong> highest priority and 254 is <strong>the</strong> lowest;<br />

lower order numbers have a higher priority)<br />

Default: If <strong>the</strong> order option is not configure, by default ACLs will<br />

have <strong>the</strong> lowest default order (255).<br />

monitor (OPTIONAL) Enter <strong>the</strong> keyword monitor to monitor traffic on <strong>the</strong><br />

monitoring interface specified in <strong>the</strong> flow-based monitoring session<br />

along with <strong>the</strong> filter operation.<br />

330 Access Control Lists

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!