Users Guide

Table Of Contents
680 Access Control Lists
Note the following additional limitations on ingress and egress ACLs:
Port ranges are not supported for egress ACLs for either IPv4 or IPv6 ACLs.
It is possible to configure mirror or redirect attributes for a given ACL rule,
but not both.
The
Dell EMC Networking N-Series switches
support a limited number
of counter resources, so it may not be possible to log every ACL rule. It is
possible to define an ACL with any number of logging rules, but the rules
that are actually logged cannot be determined until the ACL is configured
in the interface hardware. Furthermore, hardware counters that become
available after an ACL is applied are not retroactively assigned to rules that
were unable to be logged (the ACL must be disassociated from the
interface and then re-associated). Rules that are unable to be logged are
still active in the ACL for purposes of permitting or denying a matching
packet. If console logging is enabled and the severity is set to a numerically
equal or lower severity than the console severity setting, a log entry may
appear on the screen.
Maximum ACL
Rules per Interface
and Direction
(IPv6)
1021 ing., 253
egr.
378 ing., 253
egr.
1023 ing.,
509 egr.
1021 ing.,
509 egr
Maximum ACL
Rules (system-
wide)
2030 3914 3914
Maximum VLAN
interfaces with
ACLs applied
24 24 24
Maximum ACL
Logging Rules
(system-wide)
128 128 128
Table 19-2. ACL Software Limits (Continued)
Limitation Dell EMC
Networking
N1100 Series
Dell EMC
Networking
N1500 Series
Dell EMC
Networking
N2000/
N2100-
ON/N2200-ON
Series
Dell EMC
Networking
N3000-ON/
N3100-ON
Series