API Guide

Table Of Contents
IP: s=40.40.40.40 (local), d=224.0.0.5 (Te 2/11), len 64, sending broad/
multicast
proto=89
IP: s=40.40.40.40 (local), d=224.0.0.6 (Te 2/11), len 28, sending broad/
multicast
proto=2
IP: s=0.0.0.0, d=30.30.30.30, len 100, unroutable
ICMP type=8, code=0
IP: s=0.0.0.0, d=30.30.30.30, len 100, unroutable
ICMP type=8, code=0
Usage Information
To stop packets from flooding the user terminal when debugging is turned on, use the count option.
The access-group option supports only the equal to (eq) operator in TCP ACL rules. Port operators not equal
to (neq), greater than (gt), less than (lt), or range are not supported in access-group option (refer to the
following example). ARP packets (
arp) and Ether-type (ether-type) are also not supported in the access-
group option. The entire rule is skipped to compose the filter.
The access-group option pertains to:
IP protocol number: from 0 to 255
Internet control message protocol (icmp) but not the ICMP message type (from 0 to 255)
Any internet protocol (ip)
Transmission Control Protocol (tcp) but not on the rst, syn, or urg bits
User Datagram Protocol (udp)
If an ambiguous access control list rules, the debug ip packet access-control command is disabled. A
message appears identifying the error (refer to the following Example).
Example (Error
Messages)
Dell#debug ip packet access-group test
%Error: port operator GT not supported in access-list debug
%Error: port operator LT not supported in access-list debug
%Error: port operator RANGE not supported in access-list debug
%Error: port operator NEQ not supported in access-list debug
Dell#00:10:45: %RPM0-P:CP
%IPMGR-3-DEBUG_IP_PACKET_ACL_AMBIGUOUS_EXP: Ambiguous rules not
supported in access-list debug, access-list debugging is turned off
Dell#
deny arp (for Extended MAC ACLs)
Configure an egress filter that drops ARP packets on egress ACL supported line cards. (For more information, refer to your line card
documentation).
C9000 Series
Syntax
deny arp {destination-mac-address mac-address-mask | any} vlan vlan-id {ip-
address | any | opcode code-number} [count [byte]] [order] [log [interval
minutes] [threshold-in-msgs [count]] [monitor]
To remove this filter, you have two choices:
Use the no seq sequence-number command if you know the filter’s sequence number.
Use the no deny arp {destination-mac-address mac-address-mask | any} vlan vlan-
id {ip-address | any | opcode code-number} command.
Parameters
log (OPTIONAL) Enter the keyword log to enable the triggering of ACL log messages.
threshold-in msgs
count
(OPTIONAL) Enter the threshold-in-msgs keyword followed by a value to indicate
the maximum number of ACL logs that can be generated, exceeding which the generation
of ACL logs is terminated with the seq, permit, or deny commands. The threshold
range is from 1 to 100.
IPv4 Routing 877