Deployment Guide

Table Of Contents
To view an access-list that you applied to an interface, use the show ip accounting access-list command from EXEC
Privilege mode.
DellEMC(conf)#monitor session 0
DellEMC(conf-mon-sess-0)#flow-based enable
DellEMC(conf)#ip access-list ext testflow
DellEMC(config-ext-nacl)#seq 5 permit icmp any any count bytes monitor
DellEMC(config-ext-nacl)#seq 10 permit ip 102.1.1.0/24 any count bytes monitor
DellEMC(config-ext-nacl)#seq 15 deny udp any any count bytes
DellEMC(config-ext-nacl)#seq 20 deny tcp any any count bytes
DellEMC(config-ext-nacl)#exit
DellEMC(conf)#interface TenGigabitEthernet 1/1/1
DellEMC(conf-if-te-1/1/1)#ip access-group testflow in
DellEMC(conf-if-te-1/1/1)#show config
!
interface TenGigabitEthernet 1/1/1
ip address 10.11.1.254/24
ip access-group testflow in
shutdown
DellEMC(conf-if-te-1/1/1)#exit
DellEMC(conf)#do show ip accounting access-list testflow
!
Extended Ingress IP access list testflow on TenGigabitEthernet 1/1/1
Total cam count 4
seq 5 permit icmp any any monitor count bytes (0 packets 0 bytes)
seq 10 permit ip 102.1.1.0/24 any monitor count bytes (0 packets 0 bytes)
seq 15 deny udp any any count bytes (0 packets 0 bytes)
seq 20 deny tcp any any count bytes (0 packets 0 bytes)
DellEMC(conf)#do show monitor session 0
DellEMC(conf-mon-sess-0)#do show monitor session 0
SessID Source Destination Dir Mode Source IP Dest IP DSCP TTL Drop
Rate Gre-Protocol FcMonitor
------ ------ ----------- --- ---- --------- -------- ---- --- ----
---- ----------- ---------
0 Te 1/1/1 Te 1/1/1 rx Flow N/A N/A 0 0 No
N/A N/A yes
Configuring IP Mirror Access Group
To configure an IP mirror access group on an interface, use the following commands:
1. Allocate CAM profile for IPv4 ACL.
CONFIGURATION mode
cam-acl {default | l2acl number ipv4acl number ipv6acl number ipv4qos number l2qos number
l2pt number ipmacacl number [vman-qos | vman-qosdual number | vman-qosdualfp number]
ipv4pbr number} ecfmacl number [nlbclusteraclnumber]fcoeacl number iscsioptacl number
ipv4udfmirracl number | ipv4mirracl number}
2. Create a monitor session.
CONFIGURATION mode
monitor session session-ID [type { rpm | erpm [set ip dscp dscp_value | set ip ttl
ttl_value]}] [drop]
Dell(conf)#monitor session 65535 type erpm
3. Create an IP access-list.
CONFIGURATION mode
ip access-list {standard | extended} access-list-name
Dell(conf)#ip access-list standard test
4. Configure a filter to permit the IP packets.
CONFIGURATIONSTANDARDACCESSLIST mode
CONFIGURATIONEXTENDEDACCESSLIST mode
permit {source mask | any | host ip-address} {destination mask | any | host ip-address}
[count [bytes]] [dscp value] [order] [fragments] [monitor [session-id]] [no-drop]
Access Control Lists (ACLs)
123