Users Guide
Dell(conf-if-te-1/1/1)#ip access-group testflow in
Dell(conf-if-te-1/1/1)#show config
!
interface TenGigabitEthernet 1/1/1
ip address 10.11.1.254/24
ip access-group testflow in
shutdown
Dell(conf-if-te-1/1/1)#exit
Dell(conf)#do show ip accounting access-list testflow
!
Extended Ingress IP access list testflow on TenGigabitEthernet 1/1/1
Total cam count 4
seq 5 permit icmp any any monitor count bytes (0 packets 0 bytes)
seq 10 permit ip 102.1.1.0/24 any monitor count bytes (0 packets 0 bytes)
seq 15 deny udp any any count bytes (0 packets 0 bytes)
seq 20 deny tcp any any count bytes (0 packets 0 bytes)
Dell(conf)#do show monitor session 0
Dell(conf-mon-sess-0)#do show monitor session 0
SessID Source Destination Dir Mode Source IP Dest IP DSCP TTL Drop Rate
Gre-Protocol FcMonitor
------ ------ ----------- --- ---- --------- -------- ---- --- ---- ----
----------- ---------
0 Te 1/1/1 Te 1/1/1 rx Flow N/A N/A 0 0 No N/
A N/A yes
Conguring IP Mirror Access Group
To congure an IP mirror access group on an interface, use the following commands:
1 Allocate CAM prole for IPv4 ACL.
CONFIGURATION mode
cam-acl {default | l2acl number ipv4acl number ipv6acl number ipv4qos number l2qos number
l2pt number ipmacacl number [vman-qos | vman-qos—dual— number | vman-qos—dual—fp number]
ipv4pbr number} ecfmacl number [nlbclusteraclnumber]fcoeacl number iscsioptacl number
ipv4udfmirracl number}
2 Create a monitor session.
CONFIGURATION mode
monitor session session-ID [type { rpm | erpm [set ip dscp dscp_value | set ip ttl
ttl_value]}] [drop]
Dell(conf)#monitor session 65535 type erpm
3 Create an IP access-list.
CONFIGURATION mode
ip access-list {standard | extended} access-list-name
Dell(conf)#ip access-list standard test
4 Congure a lter to permit the IP packets.
CONFIGURATION—STANDARD—ACCESS—LIST mode
CONFIGURATION—EXTENDED—ACCESS—LIST mode
permit {source mask | any | host ip-address} {destination mask | any | host ip-address}
[count [bytes]] [dscp value] [order] [fragments] [monitor [session-id]] [no-drop]
Dell(config-ext-nacl)#permit ip any any count monitor 65535
5 Associate the IP access list to an interface.
126
Access Control Lists (ACLs)










