Concept Guide

seq 10 deny icmp any any
seq 15 permit 1.1.1.2
Congure Egress ACLs
Egress ACLs are applied to line cards and aect the trac leaving the system. Conguring egress ACLs onto physical interfaces protects
the system infrastructure from attack — malicious and incidental — by explicitly allowing only authorized trac. These system-wide ACLs
eliminate the need to apply ACLs onto each interface and achieves the same results. By localizing target trac, it is a simpler
implementation.
To restrict egress trac, use an egress ACL. For example, when a denial of service (DOS) attack trac is isolated to a specic interface,
you can apply an egress ACL to block the ow from the exiting the box, thus protecting downstream devices.
To create an egress ACL, use the ip access-group command in EXEC Privilege mode. The example shows viewing the conguration,
applying rules to the newly created access group, and viewing the access list.
NOTE: VRF based ACL congurations are not supported on the egress trac.
Example of Applying ACL Rules to Egress Trac and Viewing ACL Conguration
To specify ingress, use the out keyword. Begin applying rules to the ACL with the ip access-list extended abcd command. To
view the access-list, use the show command.
DellEMC(conf)#interface GigabitEthernet 1/1
DellEMC(conf-if-gi-1/1)#ip access-group abcd out
DellEMC(conf-if-gi-1/1)#show config
!
GigabitEthernet 1/1
no ip address
ip access-group abcd out
no shutdown
DellEMC(conf-if-gi-1/1)#end
DellEMC#configure terminal
DellEMC(conf)#
ip access-list extended abcd
DellEMC(config-ext-nacl)#permit tcp any any
DellEMC(config-ext-nacl)#deny icmp any any
DellEMC(config-ext-nacl)#permit 1.1.1.2
DellEMC(config-ext-nacl)#end
DellEMC#
show ip accounting access-list
!
Extended Ingress IP access list abcd on gigabitethernet 0/0
seq 5 permit tcp any any
seq 10 deny icmp any any
seq 15 permit 1.1.1.2
DellEMC#configure terminal
DellEMC(conf)#interface gigabitethernet 1/2
DellEMC(conf-if-gi-1/2)#ip vrf forwarding blue
DellEMC(conf-if-gi-1/2)#show config
!
interface GigabitEthernet 1/2
ip vrf forwarding blue
no ip address
shutdown
DellEMC(conf-if-gi-1/2)#
DellEMC(conf-if-gi-1/2)#
DellEMC(conf-if-gi-1/2)#end
DellEMC#
126
Access Control Lists (ACLs)