Users Guide

NOTE: You can congure VRF-aware ACLs on interfaces either using a range of VLANs or a range of VRFs but not both.
IP Access Control Lists (ACLs)
In Dell Networking switch/routers, you can create two dierent types of IP ACLs: standard or extended.
A standard ACL lters packets based on the source IP packet. An extended ACL lters trac based on the following criteria:
IP protocol number
Source IP address
Destination IP address
Source TCP port number
Destination TCP port number
Source UDP port number
Destination UDP port number
For more information about ACL options, refer to the Dell Networking OS Command Reference Guide.
For extended ACL, TCP, and UDP lters, you can match criteria on specic or ranges of TCP or UDP ports. For extended ACL TCP
lters, you can also match criteria on established TCP sessions.
When creating an access list, the sequence of the lters is important. You have a choice of assigning sequence numbers to the lters
as you enter them, or the Dell Networking Operating System (OS) assigns numbers in the order the lters are created. The sequence
numbers are listed in the display output of the show config and show ip accounting access-list commands.
Ingress and egress Hot Lock ACLs allow you to append or delete new rules into an existing ACL (already written into CAM) without
disrupting trac ow. Existing entries in the CAM are shued to accommodate the new entries. Hot lock ACLs are enabled by
default and support both standard and extended ACLs and on all platforms.
NOTE: Hot lock ACLs are supported for Ingress ACLs only.
CAM Usage
The following section describes CAM allocation and CAM optimization.
User Congurable CAM Allocation
CAM Optimization
User Congurable CAM Allocation
Allocate space for IPV6 ACLs by using the cam-acl command in CONFIGURATION mode.
The CAM space is allotted in lter processor (FP) blocks. The total space allocated must equal 13 FP blocks. (There are 16 FP blocks,
but System Flow requires three blocks that cannot be reallocated.)
Enter the ipv6acl allocation as a factor of 2 (2, 4, 6, 8, 10). All other prole allocations can use either even or odd numbered
ranges.
If you want to congure ACL's on VRF instances, you must allocate a CAM region using the vrfv4acl option in the cam-acl command.
Save the new CAM settings to the startup-cong (use write-mem or copy run start) then reload the system for the new
settings to take eect.
112
Access Control Lists (ACLs)