Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC Networking OS Configuration Guide for the S5048F–ON System 9.14.2.8

Configure Filters, ICMP Packets

To create a filter for ICMP packets with a specified sequence number, use the following commands.

  1. Create either an extended IPv4 or IPv6 ACL and assign it a unique name.
    CONFIGURATION mode
    ip access-list extended access-list-name
    ipv6 access-list extended access-list-name
  2. Configure an extended IP ACL filter for ICMP packets.
    CONFIG-EXT-NACL mode
    seq sequence-number {deny | permit} icmp {source mask | any | host ip-address} [count [byte]] [order] [monitor [session-id]] [fragments]
    The ICMP packets cannot be filtered using mirroring ACL.

The following example shows the configuration to filter ICMP packets using IPv4 ACL:

DellEMC(config-ext-nacl)#show config
!
ip access-list extended icmp
seq 5 permit icmp any any echo count
seq 10 permit icmp any any echo-reply count
seq 15 permit icmp any any host-unreachable count
seq 20 permit icmp any any host-unknown count
seq 25 permit icmp any any network-unknown count
seq 30 permit icmp any any net-unreachable count
seq 35 permit icmp any any packet-too-big count
seq 40 permit icmp any any parameter-problem count
seq 45 permit icmp any any port-unreachable count
seq 50 permit icmp any any source-quench count
seq 55 permit icmp any any time-exceeded count

DellEMC(config-ext-nacl)#show ip accounting access-list
!
Extended Ingress IP access list icmp on twentyFiveGigE 1/1
Total cam count 11
seq 5 permit icmp any any echo count (50 packets)
seq 10 permit icmp any any echo-reply count (50 packets)
seq 15 permit icmp any any host-unreachable count (50 packets)
seq 20 permit icmp any any host-unknown count (50 packets)
seq 25 permit icmp any any network-unknown count (50 packets)
seq 30 permit icmp any any net-unreachable count (50 packets)
seq 35 permit icmp any any packet-too-big count (50 packets)
seq 40 permit icmp any any parameter-problem count (50 packets)
seq 45 permit icmp any any port-unreachable count (50 packets)
seq 50 permit icmp any any source-quench count (50 packets)
seq 55 permit icmp any any time-exceeded count (50 packets)
DellEMC(config-ext-nacl)#show config
!
ip access-list extended icmp
seq 5 permit icmp any any echo count
seq 10 permit icmp any any echo-reply count
seq 15 permit icmp any any host-unreachable count
seq 20 permit icmp any any host-unknown count
seq 25 permit icmp any any network-unknown count
seq 30 permit icmp any any net-unreachable count
seq 35 permit icmp any any packet-too-big count
seq 40 permit icmp any any parameter-problem count
seq 45 permit icmp any any port-unreachable count
seq 50 permit icmp any any source-quench count
seq 55 permit icmp any any time-exceeded count

DellEMC(config-ext-nacl)#show ip accounting access-list
!
Extended Ingress IP access list icmp on twentyFiveGigE 1/1
Total cam count 11
seq 5 permit icmp any any echo count (50 packets)
seq 10 permit icmp any any echo-reply count (50 packets)
seq 15 permit icmp any any host-unreachable count (50 packets)
seq 20 permit icmp any any host-unknown count (50 packets)
seq 25 permit icmp any any network-unknown count (50 packets)
seq 30 permit icmp any any net-unreachable count (50 packets)
seq 35 permit icmp any any packet-too-big count (50 packets)
seq 40 permit icmp any any parameter-problem count (50 packets)
seq 45 permit icmp any any port-unreachable count (50 packets)
seq 50 permit icmp any any source-quench count (50 packets)
seq 55 permit icmp any any time-exceeded count (50 packets)

The following example shows the configuration to filter ICMPv6 packets using IPv6 ACL:

DellEMC(config-ext-nacl)#show config
!
ipv6 access-list extended icmp
seq 5 permit icmp any any echo count
seq 10 permit icmp any any echo-reply count
seq 15 permit icmp any any nd-ns count
seq 20 permit icmp any any nd-na count
seq 25 permit icmp any any packet-too-big count
seq 30 permit icmp any any parameter-problem count
seq 35 permit icmp any any time-exceeded count
seq 40 permit icmp any any dest-unreachable count
seq 45 permit icmp any any port-unreachable count

DellEMC(config-ext-nacl)#show ipv6 accounting access-list
!
Extended Ingress IPv6 access list icmpv6 on twentyFiveGigE 1/1
Total cam count 9
seq 5 permit icmp any any echo count (40 packets)
seq 10 permit icmp any any echo-reply count (50 packets)
seq 15 permit icmp any any nd-ns count (30 packets)
seq 20 permit icmp any any nd-na count (56 packets)
seq 25 permit icmp any any packet-too-big count (25 packets)
seq 30 permit icmp any any parameter-problem count (34 packets)
seq 35 permit icmp any any time-exceeded count (56 packets)
seq 40 permit icmp any any dest-unreachable count (43 packets)
seq 45 permit icmp any any port-unreachable count (25 packets)
DellEMC(config-ext-nacl)#show config
!
ipv6 access-list extended icmp
seq 5 permit icmp any any echo count
seq 10 permit icmp any any echo-reply count
seq 15 permit icmp any any nd-ns count
seq 20 permit icmp any any nd-na count
seq 25 permit icmp any any packet-too-big count
seq 30 permit icmp any any parameter-problem count
seq 35 permit icmp any any time-exceeded count
seq 40 permit icmp any any dest-unreachable count
seq 45 permit icmp any any port-unreachable count

DellEMC(config-ext-nacl)#show ipv6 accounting access-list
!
Extended Ingress IPv6 access list icmpv6 on twentyFiveGigE 1/1
Total cam count 9
seq 5 permit icmp any any echo count (40 packets)
seq 10 permit icmp any any echo-reply count (50 packets)
seq 15 permit icmp any any nd-ns count (30 packets)
seq 20 permit icmp any any nd-na count (56 packets)
seq 25 permit icmp any any packet-too-big count (25 packets)
seq 30 permit icmp any any parameter-problem count (34 packets)
seq 35 permit icmp any any time-exceeded count (56 packets)
seq 40 permit icmp any any dest-unreachable count (43 packets)
seq 45 permit icmp any any port-unreachable count (25 packets)

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\