Administrator Guide

Table Of Contents
log (OPTIONAL, E-Series only) Enter the keyword log to enter ACL matches in the
log. Supported on Jumbo-enabled line cards only.
dscp (OPTIONAL) Enter the keyword dcsp to match to the IP DCSCP values.
order (OPTIONAL) Enter the keyword order to specify the QoS order for the ACL
entry. The range is from 0 to 254 (where 0 is the highest priority and 254 is the
lowest; lower-order numbers have a higher priority). If you do not use the keyword
order, the ACLs have the lowest order by default (255).
monitor (OPTIONAL) Enter the keyword monitor when the rule is describing the traffic
that you want to monitor and the ACL in which you are creating the rule is applied
to the monitored interface.
NOTE: For more information, refer to the Flow-based Monitoring section in
the Port Monitoring chapter of the Dell Networking OS Configuration Guide.
fragments Enter the keyword fragments to use ACLs to control packet fragments.
Defaults Not configured
Command Modes CONFIGURATION-EXTENDED-ACCESS-LIST
Command
History
This guide is platform-specific. For command information about other platforms, refer to the relevant Dell
Networking OS Command Line Reference Guide.
The following is a list of the Dell Networking OS version history for this command.
Version Description
9.7(0.0) Introduced on the S6000ON.
9.0.2.0 Introduced on the S6000.
8.3.19.0 Introduced on the S4820T.
8.3.11.1 Introduced on the Z9000.
8.3.7.0 Introduced on the S4810.
8.3.1.0 Add the DSCP value for ACL matching.
8.2.1.0 Allows ACL control of fragmented packets for IP (Layer 3) ACLs.
8.1.1.0 Introduced on the E-Series ExaScale.
7.6.1.0 Introduced on the S-Series.
7.5.1.0 Introduced on the C-Series.
7.4.1.0 Added support for the non-contiguous mask and added the monitor option.
Deprecated the keyword established.
6.5.10 Expanded to include the optional QoS order priority for the ACL entry.
Usage
Information
The monitor option is relevant in the context of flow-based monitoring only. For more information, refer
to Port Monitoring.
The order option is relevant in the context of the Policy QoS feature only. The following applies:
The seq sequence-number command is applicable only in an ACL group.
The order option works across ACL groups that are applied on an interface via the QoS policy
framework.
The order option takes precedence over seq sequence-number.
If you do not configure sequence-number, the rules with the same order value are ordered
according to their configuration order.
If you configure sequence-number, the sequence-number is used as a tie breaker for rules with the
same order.
When you use the log option, the CP processor logs details about the packets that match. Depending on
how many packets match the log entry and at what rate, the CP may become busy as it has to log these
packets details.
174 Access Control Lists (ACL)