19.10.2013 Views

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Note: If an interface is configured as a “vlan-stack access” port, the packets are filtered by an<br />

L2 ACL only. The L3 ACL applied to such a port does not affect traffic. That is, existing rules<br />

for other features (such as trace-list, PBR, and QoS) are applied accordingly to the permitted<br />

traffic.<br />

For information on Layer 2 or MAC ACLs, refer to MAC Addressing and MAC Access Lists on page 151.<br />

Assign an IP ACL to an Interface<br />

To pass traffic through a configured IP ACL, you must assign that ACL to a physical or port channel<br />

interface. The IP ACL is applied to all traffic entering a physical or port channel interface and the traffic is<br />

either forwarded or dropped depending on the criteria and actions specified in the ACL.<br />

The same ACL may be applied to different interfaces and that changes its functionality. For example, you<br />

can take ACL "ABCD", and apply it using the in keyword and it becomes an ingress access list. If you<br />

apply the same ACL using the out keyword, it becomes an egress access list. If you apply the same ACL<br />

to the loopback interface, it becomes a loopback access list.<br />

This chapter covers the following topics:<br />

• Configuring Ingress ACLs on page 256<br />

• Configuring Egress ACLs on page 257<br />

• Configuring ACLs to Loopback on page 259<br />

For more information on Layer-3 interfaces, refer to Chapter 9, Interfaces, on page 175.<br />

To apply an IP ACL (standard or extended) to a physical or port channel interface, use these commands in<br />

the following sequence in the INTERFACE mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 interface interface slot/port CONFIGURATION Enter the interface number.<br />

2 ip address ip-address INTERFACE Configure an IP address for the interface,<br />

placing it in Layer-3 mode.<br />

3<br />

4<br />

ip access-group<br />

access-list-name {in | out}<br />

[implicit-permit] [vlan<br />

vlan-range]<br />

ip access-list [standard |<br />

extended] name<br />

INTERFACE Apply an IP ACL to traffic entering or exiting<br />

an interface.<br />

• out: configure the ACL to filter outgoing<br />

traffic. This keyword is supported only on<br />

E-Series.<br />

Note: The number of entries allowed per<br />

ACL is hardware-dependent. Refer to<br />

your line card documentation for detailed<br />

specification on entries allowed per ACL.<br />

INTERFACE Apply rules to the new ACL.<br />

FTOS Configuration Guide, version <strong>7.6.1.0</strong> 255

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!