Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell Configuration Guide for the S4048–ON System 9.14.2.4

PDF

Configuring UDF ACL

To configure a User Defined Field (UDF) ACL:

  1. Enable UDF ACL feature on a switch.
    CONFIGURATION mode
    feature udf-acl
    DellEMC(conf)#feature udf-acl
  2. Change the default CAM allocation settings or reconfigure new CAM allocation settings and enable IPV4 UDF.
    CONFIGURATION mode
    cam-acl {default | l2acl number ipv4acl number ipv6acl number ipv4qos number l2qos number l2pt number ipmacacl number [vman-qos | vman-dual-qos number] ecfmacl number [nlbclusteracl number] ipv4pbr number }openflow number | fcoe number} [ipv4udfenable] [iscsioptacl number] [vrfv4acl number]
    DellEMC(conf)#cam-acl l2acl 1 ipv4acl 8 ipv6acl 2 ipv4qos 0 l2qos 2 l2pt 0 ipmacacl 0 vman-qos 0 ecfmacl 0 ipv4udfenable
  3. View the currently configured CAM allocation.
    EXEC mode
    EXEC Privilege mode
    show cam-acl
    DellEMC#show cam-acl
    -- Chassis Cam ACL --
                Current Settings(in block sizes)   Next Boot(in block sizes)
                       1 block = 256 entries
    L2Acl        :         2                           1
    Ipv4Acl      :         2                           8(UdfEnabled)
    Ipv6Acl      :         0                           2
    Ipv4Qos      :         2                           0
    L2Qos        :         1                           2
    L2PT         :         0                           0
    IpMacAcl     :         0                           0
    VmanQos      :         0                           0
    EcfmAcl      :         2                           0
    FcoeAcl      :         4                           0
    iscsiOptAcl  :         0                           0
    ipv4pbr      :         0                           0
    vrfv4Acl     :         0                           0
    Openflow     :         0                           0
    fedgovacl    :         0                           0
    nlbclusteracl:         0                           0
    
    -- stack-unit 1 --
    			Current Settings(in block sizes)  Next Boot(in block sizes)
                       1 block = 256 entries
    L2Acl        :         2                           1
    Ipv4Acl      :         2                           8(UdfEnabled)
    Ipv6Acl      :         0                           2
    Ipv4Qos      :         2                           0
    L2Qos        :         1                           2
    L2PT         :         0                           0
    IpMacAcl     :         0                           0
    VmanQos      :         0                           0
    EcfmAcl      :         2                           0
    FcoeAcl      :         4                           0
    iscsiOptAcl  :         0                           0
    ipv4pbr      :         0                           0
    vrfv4Acl     :         0                           0
    Openflow     :         0                           0
    fedgovacl    :         0                           0
    nlbclusteracl:         0                           0
    
    DellEMC#
  4. Create a UDF packet format in the UDF TCAM table.
    CONFIGURATION mode
    udf-tcam name seq number
    DellEMC(conf)#udf-tcam ipnip seq 1
  5. Configure a UDF ID to parse packet headers using the specified number of offset and required bytes.
    CONFIGURATION-UDF TCAM mode
    key description udf-id id packetbase PacketBase offset bytes length bytes
    DellEMC(conf-udf-tcam)#key innerL3header udf-id 6 packetbase innerL3Header offset 0 length 2
  6. View the UDF TCAM configuration.
    CONFIGURATION-UDF TCAM mode
    show config
    DellEMC(conf-udf-tcam)#show config
    !
    udf-tcam ipnip seq 1
    key innerL3header udf-id 6 packetbase innerL3Header offset 0 length 2
    DellEMC(conf-udf-tcam)#
  7. Configure the match criteria for the packet type in which UDF offset bytes are parsed.
    CONFIGURATION-UDF TCAM mode
    match l2ethertype ipv4 ipprotocol value vlantag tagStatus
    DellEMC(conf-udf-tcam)#match l2ethertype ipv4 ipprotocol 4 vlantag any
  8. View the UDF TCAM configuration.
    CONFIGURATION-UDF TCAM mode
    show config
    DellEMC(conf-udf-tcam)#show config
    !
    udf-tcam ipnip seq 1
    match l2ethertype ipv4 ipprotocol 4 vlantag any
    DellEMC(conf-udf-tcam)#
  9. Create a UDF qualifier to assign values to UDF IDs.
    CONFIGURATION-UDF TCAM mode
    udf-qualifier-value name
    DellEMC(conf-udf-tcam)# udf-qualifier-value ipnip_val1
  10. Assign a value to a UDF ID.
    CONFIGURATION-UDF-Qualifier-Value Profile mode
    udf-id 1-12 value mask
    DellEMC(conf-udf-tcam-qual-val)#udf-id 1 aa ff
  11. Associate the UDF qualifier value with a UDF packet profile in an IP access list.
    CONFIGURATION-STANDARD-ACCESS-LIST mode
    CONFIGURATION-EXTENDED-ACCESS-LIST mode
    permit ip {source mask | any | host ip-address} {destination mask | any | host ip-address} udf-pkt-format name udf-qualifier-value name
    DellEMC(config-ext-nacl)#permit ip any any udf-pkt-format ipinip udf-qualifier-value ipnip_val1
  12. View the UDF TCAM configuration.
    CONFIGURATION-UDF TCAM mode
    show config
    DellEMC(config-ext-nacl)#show config
    !
    ip access-list extended aa
    seq 5 permit ip any any udf-pkt-format ipnip udf-qualifier-value ipnip_val1
    DellEMC(config-ext-nacl)#

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\