Ip Access-List Extended - Dell C9000 Series Reference Manual

Networking command-line reference guide
Hide thumbs Also See for C9000 Series:
Table of Contents

Advertisement

ports is configured in the CAM based on bit mask boundaries; the space required
depends on exactly what ports are included in the range.
Example
An ACL rule with a TCP port range of 4000–8000 uses eight entries in the CAM.
Rule#
1 0000111110100000 1111111111100000 4000 4031 32
2 0000111111000000 1111111111000000 4032 4095 64
3 0001000000000000 1111100000000000 4096 6143 2048
4 0001100000000000 1111110000000000 6144 7167 1024
5 0001110000000000 1111111000000000 7168 7679 512
6 0001111000000000 1111111100000000 7680 7935 256
7 0001111100000000 1111111111000000 7936 7999 64
8 0001111101000000 1111111111111111 8000 8000 1
Total Ports: 4001
Example
An ACL rule with a TCP port lt 1023 uses only one entry in the CAM.
Rule# Data
1 0000000000000000 1111110000000000 0
Total Ports: 1024
Related
deny
Commands
deny tcp

ip access-list extended

Configure an extended IP access list (IP ACL) based on IP addresses or protocols.
C9000 Series
Syntax
ip access-list extended access-list-name [cpu-qos]
To delete an access list, use the no ip access-list extended access-list-
name [cpu-qos] command.
Parameters
access-list-name
cpu-qos
Defaults
All access lists contain an implicit "deny any"; that is, if no match occurs, the packet is
dropped.
Data
— assigns a filter to deny IP traffic.
— assigns a filter to deny TCP traffic.
Enter a string up to 140 characters long as the access list name.
Enter the keyword cpu-qos to configure an extended IP ACL to
be used only to filter protocol traffic for control-plane policing
(CoPP).
Mask
From To #Covered
Mask
From To
1023 1024
Access Control Lists (ACL)
#Covered
302

Advertisement

Table of Contents
loading

Table of Contents