19.10.2013 Views

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

V<br />

For extended ACL TCP and UDP filters, you can match criteria on specific or ranges of TCP or UDP<br />

ports. For extended ACL TCP filters, you can also match criteria on established TCP sessions.<br />

When creating an access list, the sequence of the filters is important. You have a choice of assigning<br />

sequence numbers to the filters as you enter them, or FTOS will assign numbers in the order the filters are<br />

created. The sequence numbers, whether configured or assigned by FTOS, are listed in the show config<br />

and show ip accounting access-list command display output.<br />

Ingress and egress Hot Lock ACLs allow you to appending or deleting new rules into an existing ACL<br />

(already written into CAM) without disruption to traffic flow. Existing entries in CAM simply are shuffled<br />

to accommodate new entries. Hot Lock ACLs are enabled by default and support both standard and<br />

extended ACLs.<br />

E-Series <br />

C-Series No<br />

S-Series No<br />

Platform Specific Feature: Hot Lock ACLs are supported on E-Series only.<br />

Implementation Information<br />

In the E-Series, you can assign one IP ACL per interface. If an ACL is not assigned to any interface, it is<br />

not used by the software in any other capacity.<br />

The number of entries allowed per ACL is hardware-dependent. Refer to your line card documentation for<br />

detailed specification on entries allowed per ACL.<br />

For the following features if counters are enabled on rules that are already configured, when a new rule is<br />

either inserted or prepended, all the existing counters are reset:<br />

• L2 Ingress Access list<br />

• L3 Egress Access list<br />

• L2 Egress Access list<br />

If a rule is simply appended then the existing counters are not affected.<br />

Note: IP ACLs are supported over VLANs in Version 6.2.1.1 and higher.<br />

ACL Optimization<br />

If an access list contains duplicate entries, FTOS deletes one entry to conserve CAM space.<br />

Configuration Task List for IP ACLs<br />

To configure an ACL, use commands in the IP ACCESS LIST mode and the INTERFACE mode. The<br />

following list includes the configuration tasks for IP ACLs:<br />

248 IP Access Control Lists, Prefix Lists, and Route-maps

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!