Reference Guide

Table Of Contents
Column Meaning
consider an ACL with three rules, after matching rule 2, counters for rule 3
would not be incremented).
For ACL counters, if an ACL rule is configured without RATE-LIMIT, the
counter value is count of forwarded/discarded packets. (Example: If burst of
100 packets sent from IXIA, Counter value is 100).
And if ACL rule is configured with RATE LIMIT, the counter value will be the
MATCHED packet count. If the sent trac rate exceeds the configured limit,
counters would still display matched packet count (despite getting dropped
beyond the configured limit since match criteria is met) which would equal
the sent rate. For example, if rate limit is set to 10 kbps and ‘matching’ trac
is sent at 100 kbps, counters would reflect 100 kbps value. If the sent trac
rate is less than the configured limit, counters display only matched packet
count. Either way, only matched packet count is reflected in the counters,
irrespective of whether they get dropped or forwarded. ACL counters do not
interact with diserv policies.
The following example shows CLI display output for the command.
(Extreme 220) (Routing) #show ip access-lists ip1
ACL Name: ip1
Inbound Interface(s): 1/0/30
Sequence Number: 1
Action......................................... permit
Match All...................................... FALSE
Protocol....................................... 1(icmp)
ICMP Type.......................................3(Destination Unreachable)
Starting Source L4 port.........................80
Ending Source L4 port...........................85
Starting Destination L4 port....................180
Ending Destination L4 port......................185
ICMP Code.......................................0
Fragments.......................................FALSE
Committed Rate................................. 32
Committed Burst Size........................... 16
ACL hit count ..................................0
show access-lists
This command displays IP ACLs, IPv6 ACL
s, and MAC access control lists information for a designated
interface and direction. Instead of unit/slot/port, lag lag-intf-num can be used as an alternate way
to specify the LAG interface. lag lag-intf-num can also be used to specify the LAG interface where
lag-intf-num is the LAG port number. Use the control-plane keyword to display the ACLs
applied on the CPU port.
Format
show access-lists interface {unit/slot/port in | out |
control-plane}
Mode Privileged EXEC
Column Meaning
ACL Type Type of access list (IP, IPv6, or MAC).
Quality of Service Commands
ExtremeSwitching 200 Series: Command Reference Guide for version 01 .02.04.0007 640