Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell SmartFabric OS10 User Guide Release 10.5.4

PDF

Ingress ACL filters

Ingress ACL filters affect the traffic that is directly connected towards source. In the following example, an ingress IP ACL on VLAN 2 cannot block traffic in the direction from host1 to server 1 because source is directly connected on VLAN 2. To block traffic from host 1, you must apply ingress ACL on L3 port or egress ACL on VLAN 2.

To create an ingress ACL filter, use the ip access-group command in EXEC mode. To configure ingress, use the in keyword. Apply rules to the ACL with the ip access-list acl-name command. To view the access-list, use the show access-lists command.

  1. Apply an ingress access-list on the interface in INTERFACE mode.
    ip access-group access-group-name in
  2. Return to CONFIGURATION mode.
    exit
  3. Create the access-list in CONFIGURATION mode.
    ip access-list access-list-name
  4. Create the rules for the access-list in ACCESS-LIST mode.
    permit ip host ip-address host ip-address count

Apply ACL rules to access-group and view access-list

OS10(config)# interface ethernet 1/1/28
OS10(conf-if-eth1/1/28)# ip access-group abcd in
OS10(conf-if-eth1/1/28)# exit
OS10(config)# ip access-list acl1 
OS10(conf-ipv4-acl)# permit ip host 10.1.1.1 host 100.1.1.1 count

Configuration notes

Dell PowerSwitch S4200-ON Series:
  • The following applications require ACL tables: VLT, iSCSI, L2 ACL, L3 v4 ACL, L3 v6 ACL, PBR v4, PBR v6, QoS L2, QoS L3, and FCoE. In ingress ACL, you can create ACL tables for two or three applications at a time.
  • When a packet matches more than one ACL table, the system increments the counter for the table with the highest priority.
  • In IPv6 user ACL, PBR v6 ACL, and IPv6 QoS tables—destination-port, l4-source-port, flow label, and TCP flags are not supported.
  • IP fragment supports only two options: non-fragment and head/non-head.
  • IP ACL applied to SVI interface effects L2 switch traffic also.

Dell PowerSwitch S5200-ON Series:

When you configure QoS service-policy on an S5200-ON switch that is in a VLT setup with MAC and IP ACLs configured, an error appears. This issue occurs because of ACL group width limitation in the S5200-ON series switches. VLT, IP, MAC, and QoS ACLs require double-width ACL table slice. The S5200-ON series switches support only three applications that require double-wide ACL table slice at a time. An error appears because the QoS application configuration requires a fourth ACL table slice.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\