Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC SmartFabric OS10 User Guide Release 10.5.1

PDF

Egress ACL filters

Egress ACL filters affect the traffic leaving the network. Configuring egress ACL filters onto physical interfaces protects the system infrastructure from a malicious and intentional attack by explicitly allowing only authorized traffic. These system-wide ACL filters eliminate the need to apply ACL filters onto each interface.

You can use an egress ACL filter to restrict egress traffic. For example, when you isolate denial of service (DoS) attack traffic to a specific interface, and apply an egress ACL filter to block the DoS flow from exiting the network, you protect downstream devices.

  1. Apply an egress access-list on the interface in INTERFACE mode.
    ip access-group access-group-name out
  2. Return to CONFIGURATION mode.
    exit
  3. Create the access-list in CONFIGURATION mode.
    ip access-list access-list-name
  4. Create the rules for the access-list in ACCESS-LIST mode.
    seq 10 deny ip any any count fragment

Apply rules to ACL filter

OS10(config)# interface ethernet 1/1/29
OS10(conf-if-eth1/1/29)# ip access-group egress out
OS10(conf-if-eth1/1/29)# exit
OS10(config)# ip access-list egress
OS10(conf-ipv4-acl)# seq 10 deny ip any any count fragment

View IP ACL filter configuration

OS10# show ip access-lists out 
Egress IP access-list abcd
 Active on interfaces :
  ethernet1/1/29
 seq 10 deny ip any any fragment count (100 packets)

Configuration notes

Dell EMC PowerSwitch S4200-ON Series:
  • You can create either Layer 2 ACL or Layer 3 ACL. You cannot create both the tables at a time.
  • In egress L3 IPv4 ACL, the fragment, TCP flags, and DSCP fields are not supported.
  • In egress ACLs, L2 user table is utilized only for switched packets and L3 user table is utilized only for routed packets.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\