Deployment Guide

Table Of Contents
MONITOR SESSION mode
ip access-group access-list-name
To view an access-list that you applied to an interface, use the show ip accounting access-list command from EXEC
Privilege mode.
DellEMC(conf)#monitor session 0
DellEMC(conf-mon-sess-0)#flow-based enable
DellEMC(conf)#ip access-list ext testflow
DellEMC(config-ext-nacl)#seq 5 permit icmp any any count bytes monitor
DellEMC(config-ext-nacl)#seq 10 permit ip 102.1.1.0/24 any count bytes monitor
DellEMC(config-ext-nacl)#seq 15 deny udp any any count bytes
DellEMC(config-ext-nacl)#seq 20 deny tcp any any count bytes
DellEMC(config-ext-nacl)#exit
DellEMC(conf)#interface tengigabitethernet 1/1/1/1
DellEMC(conf-if-te-1/1/1/1)#ip access-group testflow in
DellEMC(conf-if-te-1/1/1/1)#show config
!
interface TenGigabitEthernet 1/1/1/1
ip address 10.11.1.254/24
ip access-group testflow in
shutdown
DellEMC(conf-if-te-1/1/1/1)#exit
DellEMC(conf)#do show ip accounting access-list testflow
!
Extended Ingress IP access list testflow on TenGigabitEthernet 1/1/1/1
Total cam count 4
seq 5 permit icmp any any 40 monitor 40 count bytes (0 packets 0 bytes)
seq 10 permit ip 102.1.1.0/24 any monitor 40 count bytes (0 packets 0 bytes)
seq 15 deny udp any any count bytes (0 packets 0 bytes)
seq 20 deny tcp any any count bytes (0 packets 0 bytes)
DellEMC(conf)#do show monitor session 0
SessionID Source Destination Direction Mode Source IP Dest IP DSCP
TTL Drop Rate Gre-Protocol FcMonitor
--------- ------ ----------- --------- ---- --------- -------- ----
--- ---- ---- ----------- ---------
0 Te 1/1/1/1 Te 1/1/2/1 rx interface 0.0.0.0 0.0.0.0 0 0
No N/A N/A yes
The following is sample configuration for flow-based mirroring with ACLs applied to monitor sessions.
monitor session 16383 type erpm
ip access-group acl3
source Port-channel 10 direction rx
erpm source-ip 20.20.20.1 dest-ip 8.1.1.2 gre-protocol 65535
flow-based enable
no disable
DellEMC#show run acl
!
ip access-list extended acl2
seq 10 permit tcp any 2.1.1.0/24 lt 140 count bytes monitor
!
ip access-list extended acl3
seq 15 permit udp 4.1.1.0/24 any neq 150 count bytes monitor
!
ip access-list extended acl4
seq 20 permit ip any any count bytes monitor
DellEMC(conf)#do show ip access-lists in
Extended Ingress IP access list acl3
seq 15 permit udp 4.1.1.0/24 any neq 150 monitor count bytes (6400 bytes)
DellEMC(conf)#
DellEMC(conf)#do show ip accounting access-list
!
Extended Ingress IP mirror access list acl3 on TenGigabitEthernet 1/1/1/4
Total cam count 16
seq 15 permit udp 4.1.1.0/24 any neq 150 monitor count bytes (6400 bytes)
666
Port Monitoring