108 | Access Control Lists (ACL)
www.dell.com | support.dell.com
Defaults
Not configured
Command Modes
CONFIGURATION-IP ACCESS-LIST-EXTENDED
Command
History
Usage
Information
The order option is relevant in the context of the Policy QoS feature only. For more information, refer 
to the Quality of Service (QoS) chapter of the FTOS Configuration Guide.
In the MXL Switch, you can configure either count (packets) or count (bytes). However, for an ACL 
with multiple rules, you can configure some ACLs with count (packets) and others as count (bytes) at 
any given time.
Most ACL rules require one entry in the CAM. However, rules with TCP and UDP port operators (gt, 
lt
, range) may require more than one entry. The range of ports is configured in the CAM based on bit 
mask boundaries; the space required depends on exactly what ports are included in the range. 
any Enter the keyword any to specify that all routes are subject to the filter.
host ip-address Enter the keyword host followed by the IP address to specify a host IP address.
dscp
Enter this keyword to deny a packet based on DSCP value.
Range: 0-63
operator
(OPTIONAL) Enter one of the following logical operand:
•
eq = equal to
•
neq = not equal to
•
gt = greater than 
•
lt = less than
•
range = inclusive range of ports
 
port port
(OPTIONAL) Enter the application layer port number. Enter two port numbers if 
using the 
range logical operand. 
Range: 0 to 65535
destination
Enter the IP address of the network or host to which the packets are sent.
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask, when specified in 
A.B.C.D format, may be either contiguous or non-contiguous. 
count (OPTIONAL) Enter the keyword count to count packets processed by the filter.
byte (OPTIONAL) Enter the keyword byte to count bytes processed by the filter.
order (OPTIONAL) Enter the keyword order to specify the QoS priority for the ACL 
entry.
Range: 0-254 (where 0 is the highest priority and 254 is the lowest; lower order 
numbers have a higher priority)
Default:  If the order keyword is not used, the ACLs have the lowest order by 
default (255).
fragments
Enter the keyword fragments to use ACLs to control packet fragments.
Version 8.3.16.1 Introduced on MXL 10/40GbE Switch IO Module