Reference Guide

Table Of Contents
Note
For IPv4, the following are not supported for egress ACLs:
A match on port ranges.
The rate-limit command.
The time-range parameter allows imposing time limitation on the IP ACL rule as defined by the
specified time range. If a time range with the specified name does not exist and the ACL containing this
ACL rule is applied to an interface or bound to a VLAN, then the ACL rule is applied immediately. If a
time range with specified name exists and the ACL containing this ACL rule is applied to an interface or
bound to a VLAN, then the ACL rule is applied when the time-range with specified name becomes
active. The ACL rule is removed when the time-range with specified name becomes inactive. For
information about configuring time ranges, see Time Range Commands for Time-Based ACLs on page
653.
The assign-queue parameter allows specification of a particular hardware queue for handling trac that
matches this rule. The allowed queue-id value is 0-(n-1), where n is the number of user configurable
queues available for the hardware platform. The assign-queue parameter is valid only for a permit rule.
The permit command’s optional attribute rate-limit allows you to permit only the allowed rate of trac
as per the configured rate in kbps, and burst-size in kbytes.
Parameter Description
sequence-number
The sequence-number specifies the sequence number for the
ACL rule. The sequence number is specified by the user or is
generated by device.
If a sequence number is not specified for the rule, a sequence
number that is 10 greater than the last sequence number in
ACL is used and this rule is placed at the end of the list. If this
is the first ACL rule in the given ACL, a sequence number of
10 is assigned. If the calculated sequence number exceeds
the maximum sequence number value, the ACL rule creation
fails. A rule cannot be created that duplicates an already
existing one and a rule cannot be configured with a sequence
number that is already used for another rule.
For example, if user adds new ACL rule to ACL without
specifying a sequence number, it is placed at the bottom of
the list. By changing the sequence number, the user can
move the ACL rule to a dierent position in the ACL.
{deny | permit} Specifies whether the IP ACL rule permits or denies the
matching trac.
every Match every packet.
{eigrp | gre | icmp | igmp | ip
| ipinip | ospf | pim | tcp |
udp | 0 -255}
Specifies the protocol to match for the IP ACL rule.
srcip srcmask | any | host srcip Specifies a source IP address and source netmask to match
for the IP ACL rule.
Specifying “any” implies specifying srcip as “0.0.0.0” and
srcmask as “255.255.255.255”.
Specifying “host A.B.C.D” implies srcip as “A.B.C.D” and
srcmask as “0.0.0.0”.
Quality of Service Commands
ExtremeSwitching 200 Series: Command Reference Guide for version 01 .02.04.0007 633