display acl

Use display acl to display configuration and match statistics for ACLs.

Syntax

display acl [ ipv6 ] { acl-number | all | name acl-name }

Views

Any view

Predefined user roles

network-admin

network-operator

mdc-admin

mdc-operator

Parameters

acl-number: Specifies an ACL by its number:

all: Displays information about all IPv4 basic, IPv4 advanced, Ethernet frame header, and user-defined ACLs if you do not specify the ipv6 keyword, or displays information about all IPv6 basic and IPv6 advanced ACLs if you specify the ipv6 keyword.

name acl-name: Specifies an ACL by its name. The acl-name argument is a case-insensitive string of 1 to 63 characters. It must start with an English letter. For a basic ACL or advanced ACL, if you do not specify the ipv6 keyword, this option specifies the name of an IPv4 basic ACL or advanced ACL. If you specify the ipv6 keyword, this option specifies the name of an IPv6 basic ACL or advanced ACL.

Usage guidelines

This command displays ACL rules in config or depth-first order, whichever is configured.

Examples

# Display configuration and match statistics for IPv4 basic ACL 2001.

<Sysname> display acl 2001
Basic ACL  2001, named flow, 1 rule, match-order is auto,
This is an IPv4 basic ACL.
ACL's step is 5
 rule 5 permit source 1.1.1.1 0 (5 times matched)
 rule 5 comment This rule is used on GigabitEthernet 5/0/1.

Table 1: Command output

Field

Description

Basic ACL 2001

Category and number of the ACL. The following field information is about IPv4 basic ACL 2000.

named flow

The name of the ACL is flow. If the ACL is not named, this field displays -none-.

1 rule

The ACL contains one rule.

match-order is auto

The match order for the ACL is auto, which sorts ACL rules in depth-first order. This field is not present when the match order is config.

This is an IPv4 basic ACL.

Description of this ACL.

ACL's step is 5

The rule numbering step is 5.

rule 5 permit source 1.1.1.1 0

Content of rule 5.

5 times matched

There have been five matches for the rule. The statistic counts only ACL matches performed in software.

This field is not displayed when no packets matched the rule.

rule 5 comment This rule is used on GigabitEthernet 5/0/1.

Comment of ACL rule 5.