Acls And Vlans; Acl Optimization; Determine The Order In Which Acls Are Used To Classify Traffic - Dell Force10 MXL Blade Configuration Manual

Configuration guide for the mxl 10/40gbe switch io module
Hide thumbs Also See for Force10 MXL Blade:
Table of Contents

Advertisement

L3 Ingress Access list
L3 Egress Access list
Note: IP ACLs are supported over VLANs in Version 6.2.1.1 and higher.
V

ACLs and VLANs

There are some differences when assigning ACLs to a VLAN rather than a physical port. For example,
when using a single port-pipe, if you apply an ACL to a VLAN, one copy of the ACL entries gets installed
in the ACL CAM on the port-pipe. The entry would look for the incoming VLAN in the packet. Whereas,
if you apply an ACL on individual ports of a VLAN, separate copies of the ACL entries are installed for
each port belonging to a port-pipe.

ACL Optimization

If an access list contains duplicate entries, FTOS deletes one of the entries to conserve CAM space.
Standard and extended ACLs take up the same amount of CAM space. A single ACL rule uses two CAM
entries whether it is identified as a standard or extended ACL.

Determine the Order in Which ACLs are Used to Classify Traffic

When you link class-maps to queues using the
according to queue priority (queue numbers closer to 0 have lower priorities). For example, in
class-map cmap2 is matched against ingress packets before cmap1.
ACLs acl1 and acl2 have overlapping rules because the address range 20.1.1.0/24 is within 20.0.0.0/8.
Therefore, (without the keyword
and are buffered in queue 7, though you intended for these packets to match positive against cmap2 and be
buffered in queue 4.
In cases such as these, where class-maps with overlapping ACL rules are applied to different queues, use
the
keyword to specify the order in which you want to apply ACL rules
order
range from 0 to 254. FTOS writes to the CAM ACL rules with lower order numbers (order numbers closer
to 0) before rules with higher order numbers so that packets are matched as you intended. By default, all
ACL rules have an order of 254.
service-queue
) packets within the range 20.1.1.0/24 match positive against cmap1
order
command, FTOS matches the class-maps
(Figure
Access Control Lists (ACLs) | 73
Figure
5-1,
5-1). The order can

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents