Users Guide
INTERFACE mode
ip access-group access-list
Example of the flow-based enable Command
To view an access-list that you applied to an interface, use the show ip accounting access-list command from EXEC Privilege
mode.
Dell(conf)#monitor session 0
Dell(conf-mon-sess-0)#flow-based enable
Dell(conf)#
ip access-list ext testflow
Dell(config-ext-nacl)#seq 5 permit icmp any any count bytes monitor
Dell(config-ext-nacl)#seq 10 permit ip 102.1.1.0/24 any count bytes monitor
Dell(config-ext-nacl)#seq 15 deny udp any any count bytes
Dell(config-ext-nacl)#seq 20 deny tcp any any count bytes
Dell(config-ext-nacl)#exit
Dell(conf)#interface TenGigabitEthernet 1/1/1
Dell(conf-if-te-1/1/1)#ip access-group testflow in
Dell(conf-if-te-1/1/1)#show config
!
interface TenGigabitEthernet 1/1/1
ip address 10.11.1.254/24
ip access-group testflow in
shutdown
Dell(conf-if-te-1/1/1)#exit
Dell(conf)#do show ip accounting access-list testflow
!
Extended Ingress IP access list testflow on TenGigabitEthernet 1/1/1
Total cam count 4
seq 5 permit icmp any any monitor count bytes (0 packets 0 bytes)
seq 10 permit ip 102.1.1.0/24 any monitor count bytes (0 packets 0 bytes)
seq 15 deny udp any any count bytes (0 packets 0 bytes)
seq 20 deny tcp any any count bytes (0 packets 0 bytes)
Dell(conf)#do show monitor session 0
Dell(conf-mon-sess-0)#do show monitor session 0
SessID Source Destination Dir Mode Source IP Dest IP DSCP TTL Drop Rate
Gre-Protocol FcMonitor
------ ------ ----------- --- ---- --------- -------- ---- --- ---- ----
----------- ---------
0 Te 1/1/1 Te 1/1/1 rx Flow N/A N/A 0 0 No N/
A N/A yes
Configuring IP Mirror Access Group
To configure an IP mirror access group on an interface, use the following commands:
1 Allocate CAM profile for IPv4 ACL.
CONFIGURATION mode
cam-acl {default | l2acl number ipv4acl number ipv6acl number ipv4qos number l2qos number
l2pt number ipmacacl number [vman-qos | vman-qos—dual— number | vman-qos—dual—fp number]
ipv4pbr number} ecfmacl number [nlbclusteraclnumber]fcoeacl number iscsioptacl number
ipv4udfmirracl number}
2 Create a monitor session.
CONFIGURATION mode
monitor session session-ID [type { rpm | erpm [set ip dscp dscp_value | set ip ttl
ttl_value]}] [drop]
Dell(conf)#monitor session 65535 type erpm
3 Create an IP access-list.
124
Access Control Lists (ACLs)










