Users Guide

Table Of Contents
2. Enable flow-based monitoring for the mirroring session in MONITOR-SESSION mode.
flow-based enable
3. Define ACL rules that include the keywords capture session session-id in CONFIGURATION mode. The system
only considers port monitoring traffic that matches rules with the keywords capture session.
ip access-list
4. Apply the ACL to the monitored port in INTERFACE mode.
ip access-group access-list
Enable flow-based monitoring
OS10(config)# monitor session 1 type local
OS10(conf-mon-local-1)# flow-based enable
OS10(config)# ip access-list testflow
OS10(conf-ipv4-acl)# seq 5 permit icmp any any capture session 1
OS10(conf-ipv4-acl)# seq 10 permit ip 102.1.1.0/24 any capture session 1 count byte
OS10(conf-ipv4-acl)# seq 15 deny udp any any capture session 2 count byte
OS10(conf-ipv4-acl)# seq 20 deny tcp any any capture session 3 count byte
OS10(conf-ipv4-acl)# exit
OS10(config)# interface ethernet 1/1/1
OS10(conf-if-eth1/1/1)# ip access-group testflow in
OS10(conf-if-eth1/1/1)# no shutdown
View access-list configuration
OS10# show ip access-lists in
Ingress IP access-list testflow
Active on interfaces :
ethernet1/1/1
seq 5 permit icmp any any capture session 1 count (0 packets)
seq 10 permit ip 102.1.1.0/24 any capture session 1 count bytes (0 bytes)
seq 15 deny udp any any capture session 2 count bytes (0 bytes)
seq 20 deny tcp any any capture session 3 count bytes (0 bytes)
View monitor sessions
OS10(conf-if-eth1/1/1)# show monitor session all
S.Id Source Destination Dir SrcIP DstIP DSCP TTL State Reason
----------------------------------------------------------------------------
1 ethernet1/1/1 ethernet1/1/4 both N/A N/A N/A N/A true Is UP
View ACL table utilization report
The show acl-table-usage detail command shows the ingress and egress ACL tables for the various features and their
utilization.
The hardware pool area displays the ingress application groups (pools), the features mapped to each of these groups, and the
amount of used and free space available in each of the pools. The amount of space required to store a single ACL rule in a pool
depends on the keywidth of the TCAM slice.
The service pool displays the amount of used and free space for each of the features. The number of ACL rules configured
for a feature is displayed in the configured rules column. The number of used rows depends on the number of ports the
configured rules are applied on. Under Allocated pools, you can view the percentage of dedicated space reserved for a particular
feature or the phrase Shared if you have not reserved space for each of the features individually, against the total number of
pools allocated for the application group. In the example given below, the SYSTEM_FLOW feature has 15 percentage of space
reserved in ingress app-group-1 with a pool count of 1, which is represented by 15:1.
OS10# show acl-table-usage detail
Ingress ACL utilization
Hardware Pools
-----------------------------------------------------------------------------------------
--------------
Pool ID App(s) Used rows Free
1452
Access Control Lists