Administrator Guide
Version Description
8.3.11.1 Introduced on the Z9000.
8.3.7.0 Introduced on the S4810.
8.3.1.0 Added the keyword dscp.
8.2.1.0 Allows ACL control of fragmented packets for IP (Layer 3) ACLs.
8.1.1.0 Introduced on the E-Series ExaScale.
6.5.1.0 Expanded to include the optional QoS order priority for the ACL entry.
Usage Information
Use the order option only when you use policy-based QoS on the switch. For more information, refer to the
Quality of Service chapter of the C9000 Series Configuration Guide.
When you use the log option, the CP processor logs detail the packets that match. Depending on how many
packets match the log entry and at what rate, the CP may become busy as it has to log these packets’ details.
Use the monitor option only when you are using flow-based monitoring. For more information, refer to the Port
Monitoring chapter of the C9000 Series Configuration Guide.
NOTE: When ACL logging and byte counters are configured simultaneously, byte counters may
display an incorrect value. Configure packet counters with logging instead.
ICMP Message
Type Keywords
ICMP Message Type Name
administratively-
prohibited
Administratively prohibited
alternate-address Alternate host address
conversion-error Datagram conversion error
dod-host-
prohibited
Host prohibited
dod-net-
prohibited
Net prohibited
echo Echo
echo-reply Echo reply
general-
parameter-
problem
Parameter problem
host-isolated Host isolated
host-precedence-
unreachable
Host unreachable for precedence
host-redirect Host redirect
host-tos-redirect Host redirect for TOS
host-tos-
unreachable
Host unreachable for TOS
host-unknown Host unknown
host-unreachable Host unreachable
information-reply Information replies
information-
request
Information requests
mask-reply Mask replies
mask-request Mask requests
Access Control Lists (ACL) 225