Deployment Guide

Table Of Contents
seq 50 permit icmp any any source-quench count
seq 55 permit icmp any any time-exceeded count
DellEMC(config-ext-nacl)#show ip accounting access-list
!
Extended Ingress IP access list icmp on TenGigabitEthernet 1/1/1
Total cam count 11
seq 5 permit icmp any any echo count (50 packets)
seq 10 permit icmp any any echo-reply count (50 packets)
seq 15 permit icmp any any host-unreachable count (50 packets)
seq 20 permit icmp any any host-unknown count (50 packets)
seq 25 permit icmp any any network-unknown count (50 packets)
seq 30 permit icmp any any net-unreachable count (50 packets)
seq 35 permit icmp any any packet-too-big count (50 packets)
seq 40 permit icmp any any parameter-problem count (50 packets)
seq 45 permit icmp any any port-unreachable count (50 packets)
seq 50 permit icmp any any source-quench count (50 packets)
seq 55 permit icmp any any time-exceeded count (50 packets)
The following example shows the configuration to filter ICMPv6 packets using IPv6 ACL:
DellEMC(config-ext-nacl)#show config
!
ipv6 access-list extended icmp
seq 5 permit icmp any any echo count
seq 10 permit icmp any any echo-reply count
seq 15 permit icmp any any nd-ns count
seq 20 permit icmp any any nd-na count
seq 25 permit icmp any any packet-too-big count
seq 30 permit icmp any any parameter-problem count
seq 35 permit icmp any any time-exceeded count
seq 40 permit icmp any any dest-unreachable count
seq 45 permit icmp any any port-unreachable count
DellEMC(config-ext-nacl)#show ipv6 accounting access-list
!
Extended Ingress IPv6 access list icmpv6 on TenGigabitEthernet 1/1/1
Total cam count 9
seq 5 permit icmp any any echo count (40 packets)
seq 10 permit icmp any any echo-reply count (50 packets)
seq 15 permit icmp any any nd-ns count (30 packets)
seq 20 permit icmp any any nd-na count (56 packets)
seq 25 permit icmp any any packet-too-big count (25 packets)
seq 30 permit icmp any any parameter-problem count (34 packets)
seq 35 permit icmp any any time-exceeded count (56 packets)
seq 40 permit icmp any any dest-unreachable count (43 packets)
seq 45 permit icmp any any port-unreachable count (25 packets)
Configure Filters, TCP Packets
To create a filter for TCP packets with a specified sequence number, use the following commands.
1. Create an extended IP ACL and assign it a unique name.
CONFIGURATION mode
ip access-list extended access-list-name
2. Configure an extended IP ACL filter for TCP packets.
CONFIG-EXT-NACL mode
seq sequence-number {deny | permit} tcp {source mask | any | host ip-address} [count
[byte]] [order] [monitor [session-id]] [fragments]
Configure Filters, UDP Packets
To create a filter for UDP packets with a specified sequence number, use the following commands.
1. Create an extended IP ACL and assign it a unique name.
Access Control Lists (ACLs)
109