Users Guide

ip access-group abcd out
no shutdown
Dell(conf-if-te-1/1/1)#end
Dell#configure terminal
Dell(conf)#ip access-list extended abcd
Dell(config-ext-nacl)#permit tcp any any
Dell(config-ext-nacl)#deny icmp any any
Dell(config-ext-nacl)#permit 1.1.1.2
Dell(config-ext-nacl)#end
Dell#
show ip accounting access-list
!
Extended Ingress IP access list abcd on gigethernet 0/0
seq 5 permit tcp any any
seq 10 deny icmp any any
seq 15 permit 1.1.1.2
Dell#configure terminal
Dell(conf)#interface te 1/2/1
Dell(conf-if-te-1/2/1)#ip vrf forwarding blue
Dell(conf-if-te-1/2/1)#show config
!
interface TenGigabitEthernet 1/2/1
ip vrf forwarding blue
no ip address
shutdown
Dell(conf-if-te-1/2/1)#
Dell(conf-if-te-1/2/1)#
Dell(conf-if-te-1/2/1)#end
Dell#
Applying Egress Layer 3 ACLs (Control-Plane)
By default, packets originated from the system are not ltered by egress ACLs.
For example, if you initiate a ping session from the system and apply an egress ACL to block this type of trac on the interface, the ACL
does not aect that ping trac. The Control Plane Egress Layer 3 ACL feature enhances IP reachability debugging by implementing
control-plane ACLs for CPU-generated and CPU-forwarded trac. Using permit rules with the count option, you can track on a per-ow
basis whether CPU-generated and CPU-forwarded packets were transmitted successfully.
1 Apply Egress ACLs to IPv4 system trac.
CONFIGURATION mode
ip control-plane [egress filter]
2 Apply Egress ACLs to IPv6 system trac.
CONFIGURATION mode
ipv6 control-plane [egress filter]
3 Create a Layer 3 ACL using permit rules with the count option to describe the desired CPU trac.
CONFIG-NACL mode
permit ip {source mask | any | host ip-address} {destination mask | any | host ip-address}
count
Dell Networking OS Behavior: Virtual router redundancy protocol (VRRP) hellos and internet group management protocol (IGMP) packets
are not aected when you enable egress ACL ltering for CPU trac. Packets sent by the CPU with the source address as the VRRP
virtual IP address have the interface MAC address instead of VRRP virtual MAC address.
Conguring UDF ACL
To congure a User Dened Field (UDF) ACL:
1 Enable UDF ACL feature on a switch.
114
Access Control Lists (ACLs)