Acl Commands; Ip Access Control List (Ip Acl) Commands - Dell Force10 S2410-01-10GE-24P Command Reference Manual

Sftos command reference
Hide thumbs Also See for Force10 S2410-01-10GE-24P:
Table of Contents

Advertisement

ACL Commands

SFTOS supports the following types of Access Control Lists (ACLs):
An Access Control List (ACL) ensures that only authorized users and types of traffic have access to
specific resources, while blocking unwarranted attempts to reach network resources.
The following conditions pertain to ACLs in SFTOS:
For details on using access control commands, see the Access Control chapter in the SFTOS
Configuration Guide. ACLs factor into quality of service. For more on quality of service (QoS), see
Quality of Service (QoS) Commands on page

IP Access Control List (IP ACL) Commands

access-list
This command creates a rule for an IP access control list (ACL). The ACL is identified by the ACL
number, represented in the syntax statement as 1-99 (IP Standard ACL) or 100-199 (IP Extended
ACL).
IP Access Control List (IP ACL) Commands
MAC Access Control List (ACL) Commands on page 384
Broadcast Storm Control Commands on page 389
ACL configuration for IP packet fragments is not supported.
The maximum number of rules per ACL translates into the number of hardware classifier entries
used when an ACL is attached to an interface. Increasing these values in the SFTOS software
increases the RAM and NVSTORE usage.
ACLs are configured separately for Layer 2 and Layer 3. Both types of ACL can be applied to the
same interface.
Wildcard masking for ACLs operates differently from a subnet mask. A wildcard mask is in
essence the inverse of a subnet mask. With a subnet mask, the mask has ones (1's) in the bit
positions that are used for the network address, and has zeros (0's) for the bit positions that are not
used. In contrast, a wildcard mask has (0's) in a bit position that must be checked. A '1' in a bit
position of the ACL mask indicates the corresponding bit can be ignored.
access-list on page 379
ip access-group (Interface) on page 381
ip access-group all on page 382
show ip access-lists on page 382
327.
21
ACL Commands | 379

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Force10

Table of Contents