White Papers

Table Of Contents
Related
Commands
deny assigns a filter to deny IP traffic.
deny tcp assigns a filter to deny TCP traffic.
ip access-list extended
Name (or select) an extended IP access list (IP ACL) based on IP addresses or protocols.
Syntax
ip access-list extended access-list-name
To delete an access list, use the no ip access-list extended access-list-name command.
Parameters
access-list-name
Enter a string up to 140 characters long as the access list name.
Defaults All access lists contain an implicit deny any; that is, if no match occurs, the packet is dropped.
Command Modes CONFIGURATION
Supported Modes FullSwitch
Command
History
Version Description
9.9(0.0) Introduced on the FN IOM.
8.3.16.1 Introduced on the MXL 10/40GbE Switch IO Module.
Usage
Information
The number of entries allowed per ACL is hardware-dependent. For detailed specification on entries
allowed per ACL, refer to your line card documentation.
Example
Dell(conf)#ip access-list extended TESTListEXTEND
Dell(config-ext-nacl)#
Related
Commands
ip access-list standard configures a standard IP access list.
resequence access-list Displays the current configuration.
permit (for Extended IP ACLs)
To pass IP packets meeting the filter criteria, configure a filter.
Syntax
permit {source mask | any | host ip-address} {destination mask | any | host
ip-address} [count [bytes]] [dscp value] [order] [fragments] [log [interval
minutes] [threshold-in-msgs [count]] [monitor]
To remove this filter, you have two choices:
Use the no seq sequence-number command if you know the filters sequence number.
Use the no deny {source mask | any | host ip-address} {destination mask |
any | host ip-address} command.
Parameters
source Enter the IP address in dotted decimal format of the network from which the
packet was sent.
mask (OPTIONAL) Enter a network mask in /prefix format (/x) or A.B.C.D. The mask,
when specified in A.B.C.D format, may be either contiguous or non-contiguous.
any Enter the keyword any to specify that all routes are subject to the filter.
host
ip-address
Enter the keyword host then the IP address to specify a host IP address or
hostname.
count (OPTIONAL) Enter the keyword count to count packets processed by the filter.
bytes (OPTIONAL) Enter the keyword bytes to count bytes processed by the filter.
158 Access Control Lists (ACL)