Administrator Guide

Table Of Contents
The order option takes precedence over seq sequence-number.
If sequence-number is not configured, the rules with the same order value are ordered according to
their configuration order.
If sequence-number is configured, the sequence-number is used as a tie breaker for rules with the
same order.
When you use the log option, the CP processor logs detail the packets that match. Depending on how
many packets match the log entry and at what rate, the CP may become busy as it has to log these
packets details.
Use the monitor option only when you are using flow-based monitoring. For more information, refer to
the Port Monitoring chapter of the C9000 Series Configuration Guide.
By default, 10 ACL logs are generated if you do not specify the threshold explicitly. The default frequency
at which ACL logs are generated is five minutes. By default, flow-based monitoring is not enabled.
NOTE: When ACL logging and byte counters are configured simultaneously, byte counters may
display an incorrect value. Configure packet counters with logging instead.
Related
Commands
deny configures a filter to drop packets.
permit configures a filter to forward packets.
ACL VLAN Group Commands
Use the commands in this section to configure ACL VLAN groups and CAM optimization for ACLs applied to VLAN groups.
acl-vlan-group
Create an ACL VLAN group.
C9000 Series
Term heading
Description heading
Syntax
acl-vlan-group group name
To remove an ACL VLAN group, use the no acl-vlan-group group name command.
Parameters
group-name
Enter the name of the ACL VLAN group (140 characters maximum).
Default None
Command Modes
ACL-VLAN-GROUP CONFIGURATION
CONFIGURATION TERMINAL BATCH
Command
History
Version Description
9.10(0.0) Introduced the Configuration Terminal Batch mode on C9010.
9.9(0.0) Introduced on the C9010.
9.5(0.1) Introduced on the Z9500.
9.3(0.0) Introduced on the S4810, S4820T, and Z9000.
Usage
Information
You can configure up to eight different ACL VLAN groups at a time on the switch. When you configure
an ACL VLAN group, you enter ACL VLAN Group configuration mode. You can also configure the ACL
VLAN group in Configuration Terminal Batch mode that applies the configurations to the chassis in a
dual-homing setup.
254 Access Control Lists (ACL)