Reference Guide

3 Dene ACL rules that include the keywords capture session session-id in CONFIGURATION mode. The system only
considers port monitoring trac that matches rules with the keywords capture session.
ip access-list
4 Apply the ACL to the monitored port in INTERFACE mode.
ip access-group access-list
Enable ow-based monitoring
OS10(config)# monitor session 1 type local
OS10(conf-mon-local-1)# flow-based enable
OS10(config)# ip access-list testflow
OS10(conf-ipv4-acl)# seq 5 permit icmp any any capture session 1
OS10(conf-ipv4-acl)# seq 10 permit ip 102.1.1.0/24 any capture session 1
OS10(conf-ipv4-acl)# seq 15 deny udp any any capture session 2
OS10(conf-ipv4-acl)# seq 20 deny tcp any any capture session 3
OS10(conf-ipv4-acl)# exit
OS10(config)# interface ethernet 1/1/1
OS10(conf-if-eth1/1/1)# ip access-group testflow in
OS10(conf-if-eth1/1/1)# no shutdown
View access-list conguration
OS10# show ip access-lists in
Ingress IP access-list testflow
Active on interfaces :
ethernet1/1/1
seq 5 permit icmp any any capture session 1
seq 10 permit ip 102.1.1.0/24 any capture session 1
seq 15 deny udp any any capture session 2
seq 20 deny tcp any any capture session 3
View monitor sessions
OS10(conf-if-eth1/1/1)# show monitor session all
S.Id Source Destination Dir SrcIP DstIP DSCP TTL State Reason
----------------------------------------------------------------------------
1 ethernet1/1/1 ethernet1/1/4 both N/A N/A N/A N/A true Is UP
ACL commands
clear ip access-list counters
Clears ACL counters for a specic access-list.
Syntax
clear ip access-list counters [access-list-name]
Parameters access-list-name — (Optional) Enter the name of the IP access-list to clear counters. A maximum of 140
characters.
Default Not congured
Command Mode EXEC
Usage Information If you do not enter an access-list name, all IPv6 access-list counters clear. The counter counts the number of
packets that match each permit or deny statement in an access-list. To get a more recent count of packets
matching an access list, clear the counters to start at zero. To view access-list information, use the show
access-lists command.
Example
OS10# clear ip access-list counters
604 Access Control Lists