メイン コンテンツに進む
  • すばやく簡単にご注文が可能
  • 注文内容の表示、配送状況をトラック
  • 会員限定の特典や割引のご利用
  • 製品リストの作成とアクセスが可能
  • 「Company Administration(会社情報の管理)」では、お使いのDell EMCのサイトや製品、製品レベルでのコンタクト先に関する情報を管理できます。

Dell EMC SmartFabric OS10 User Guide Release 10.5.0

PDF

Assign sequence number to filter

IP ACLs filter on source and destination IP addresses, IP host addresses, TCP addresses, TCP host addresses, UDP addresses, and UDP host addresses. Traffic passes through the filter by filter sequence. Configure the IP ACL by first entering IP ACCESS-LIST mode and then assigning a sequence number to the filter.

User-provided sequence number

  • Enter IP ACCESS LIST mode by creating an IP ACL in CONFIGURATION mode.
    ip access-list access-list-name
  • Configure a drop or forward filter in IPV4-ACL mode.
    seq sequence-number {deny | permit | remark} {ip-protocol-number | icmp | ip | protocol | tcp | udp} {source prefix | source mask | any | host} {destination mask | any | host ip-address} [count [byte]] [fragments]

Auto-generated sequence number

If you are creating an ACL with only one or two filters, you can let the system assign a sequence number based on the order you configure the filters. The system assigns sequence numbers to filters using multiples of ten values.

  • Configure a deny or permit filter to examine IP packets in IPV4-ACL mode.
    {deny | permit} {source mask | any | host ip-address} [count [byte]] [fragments]
  • Configure a deny or permit filter to examine TCP packets in IPV4-ACL mode.
    {deny | permit} tcp {source mask] | any | host ip-address}} [count [byte]] [fragments]
  • Configure a deny or permit filter to examine UDP packets in IPV4-ACL mode.
    {deny | permit} udp {source mask | any | host ip-address}} [count [byte]] [fragments]

Assign sequence number to filter

OS10(config)# ip access-list acl1
OS10(conf-ipv4-acl)# seq 5 deny tcp any any capture session 1 count 

View ACLs and packets processed through ACL

OS10# show ip access-lists in
Ingress IP access-list acl1
 Active on interfaces :
  ethernet1/1/5
 seq 5 permit ip any any count (10000 packets)

このコンテンツを評価する

正確
有益
分かりやすい
この記事は役に立ちましたか?
0/3000 characters
  1~5個の星の数で評価してください。
  1~5個の星の数で評価してください。
  1~5個の星の数で評価してください。
  この記事は役に立ちましたか?
  コメントでは、以下の特殊文字は利用できません: <>()\