Dell Force10 S2410-01-10GE-24P SFTOS Configuration Guide - Page 204

Restrictions on the usage of loopback interface ACL

Page 204 highlights

www.dell.com | support.dell.com To apply an ACL (standard or extended) for loopback, use the following sequence: Step Command Syntax 1 • For a Standard IP ACL: access-list 1-99 {deny | permit} {every | srcip srcmask} [log] [assign-queue queue-id] [{mirror | redirect} unit/slot/port] • For an Extended IP ACL: access-list 100-199 {deny | permit} {every | icmp | igmp | ip | tcp | udp | protocol_number} {any | srcip srcmask} {any | eq {portkey | 0-65535}{any | dstip dstmask} [eq {portkey | 0-65535}] [precedence precedence | tos tos tosmask | dscp dscp] [log] [assign-queue queue-id] [redirect unit/slot/port] 2 interface loopback 0 3 ip access-group ACLnumber [seq] in 4 show ip access-lists [ACLnumber] 5 show interface loopback 0 Command Mode Purpose Global Config Create an IP ACL. Note: The mirror option is only available for the S50V and S25P. Global Config Interface Config Privileged Exec Privileged Exec Create the loopback interface and access the Interface Config mode. Attach the specified ACL to the loopback interface. Display rules associated with the specified ACL. Display the loopback configuration. Restrictions on the usage of loopback interface ACL As noted above, applying an ACL to loopback interface 0 in turn applies the ACL to all physical interfaces. To configure additional ACLs on a physical interface, be aware that the "loopback interface ACL" might conflict with the desired physical interface ACL behavior. Example of loopback interface configuration sequence In the following example, two rules are added to ACL 2, and then ACL 2 is applied to the loopback interface. 204 | Access Control

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306

204
|
Access Control
www.dell.com | support.dell.com
To apply an ACL (standard or extended) for loopback, use the following sequence:
Restrictions on the usage of loopback interface ACL
As noted above, applying an ACL to loopback interface 0 in turn applies the ACL to all physical
interfaces. To configure additional ACLs on a physical interface, be aware that the “loopback interface
ACL” might conflict with the desired physical interface ACL behavior.
Example of loopback interface configuration sequence
In the following example, two rules are added to ACL 2, and then ACL 2 is applied to the loopback
interface.
Step
Command Syntax
Command
Mode
Purpose
1
For a Standard IP ACL:
access-list
1-99
{deny | permit} {every |
srcip
srcmask
} [log]
[assign-queue
queue-id
] [{
mirror
| redirect}
unit/slot/port
]
For an Extended IP ACL:
access-list
100-199
{
deny
|
permit
} {
every
|
icmp
|
igmp
|
ip
|
tcp
|
udp
|
protocol_number
} {
any
|
srcip
srcmask
} {
any
|
eq
{
portkey
|
0-65535
}{
any
|
dstip
dstmask
} [
eq
{
portkey
|
0-65535
}]
[
precedence
precedence
|
tos
tos
tosmask
|
dscp
dscp
] [
log
]
[
assign-queue
queue-id
] [
redirect
unit/slot/port
]
Global
Config
Create an IP ACL.
Note: The
mirror
option is only
available for the S50V
and S25P.
2
interface loopback 0
Global
Config
Create the loopback
interface and access
the Interface Config
mode.
3
ip access-group
ACLnumber
[
seq
]
in
Interface
Config
Attach the specified
ACL to the loopback
interface.
4
show ip access-lists
[
ACLnumber
]
Privileged
Exec
Display rules
associated with the
specified ACL.
5
show interface loopback 0
Privileged
Exec
Display the loopback
configuration.