100 | Access Control Lists (ACL)
www.dell.com | support.dell.com
• Use the no permit {source [mask] | any | host ip-address} command.
Parameters
Defaults
Not configured.
Command Modes
CONFIGURATION-IP ACCESS-LIST-STANDARD
Command
History
Usage
Information
The order option is relevant in the context of the Policy QoS feature only. For more information, refer
to the Quality of Service (QoS) chapter of the FTOS Configuration Guide.
In the MXL Switch, you can configure either count (packets) or count (bytes). However, for an ACL
with multiple rules, you can configure some ACLs with count (packets) and others as count (bytes) at
any given time.
Related
Commands
seq
Assign a sequence number to a deny or permit filter in an IP access list while creating the filter.
Syntax
seq sequence-number {deny | permit} {source [mask] | any | host ip-address}} [count [byte]
[dscp value] [order] [fragments]
Parameters
source
Enter the IP address in dotted decimal format of the network from which the
packet was sent.
mask
(OPTIONAL) Enter a network mask in /prefix format (/x) or A.B.C.D. The mask,
when specified in A.B.C.D format, may be either contiguous or non-contiguous.
any Enter the keyword any to specify that all routes are subject to the filter.
host ip-address Enter the keyword host followed by the IP address to specify a host IP address
or hostname.
count (OPTIONAL) Enter the keyword count to count packets processed by the filter.
dscp (OPTIONAL) Enter the keyword dscp to match to the IP DSCP values.
byte (OPTIONAL) Enter the keyword byte to count bytes processed by the filter.
order (OPTIONAL) Enter the keyword order to specify the QoS priority for the ACL
entry.
Range: 0-254 (where 0 is the highest priority and 254 is the lowest; lower
order numbers have a higher priority)
Default: If the order keyword is not used, the ACLs have the lowest order by
default (255).
Version 8.3.16.1 Introduced on MXL 10/40GbE Switch IO Module
deny Assign an IP ACL filter to deny IP packets.
ip access-list standard Create a standard ACL.
sequence-number
Enter a number from 0 to 4294967290.
Range: 0 to 65534
deny Enter the keyword deny to configure a filter to drop packets meeting this
condition.
permit Enter the keyword permit to configure a filter to forward packets meeting this
criteria.