Configure the access control entry (ACE) action mode as deny or permit.
default filter acl ace action <1-2048> <1-2000> { permit | deny } internal-qos
default filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt
default filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt count
default filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt count redirect-next-hop
default filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt redirect-next-hop
default filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt redirect-next-hop unreachable
default filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-ports
default filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop
default filter acl ace action <1-2048> <1-2000> { permit | deny } remark-dot1p
default filter acl ace action <1-2048> <1-2000> { permit | deny } remark-dscp
default filter acl ace action <1-2048> <1-2000> { permit | deny }
default filter acl ace action <1-2048> <1-2000> { permit | deny } count
filter acl ace action <1-2048> <1-2000> { permit | deny }
filter acl ace action <1-2048> <1-2000> { permit | deny } count
filter acl ace action <1-2048> <1-2000> { permit | deny } internal-qos <0-7>
filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt <1-512>
filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-ports {slot/port[/sub-port][-slot/port[/sub-port]][,...][slot/all][all]}
filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop WORD<1-45>
filter acl ace action <1-2048> <1-2000> { permit | deny } remark-dot1p <0-7>
filter acl ace action <1-2048> <1-2000> { permit | deny } remark-dscp <0-256 | 0-256>
filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop WORD<1-45> [count | unreachable | vrf {WORD <1-16>}]
filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop WORD<1-45> unreachable { permit | deny }
filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop WORD<1-45> unreachable { permit | deny } count
filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop WORD<1-45> vrf WORD <1-16> unreachable { permit | deny }
filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop WORD<1-45> vrf WORD <1-16> unreachable { permit | deny } count
no filter acl ace action <1-2048> <1-2000> { permit | deny }
no filter acl ace action <1-2048> <1-2000> { permit | deny } count
no filter acl ace action <1-2048> <1-2000> { permit | deny } internal-qos
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt count
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt count [log [redirect-next-hop]]
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt count redirect-next-hop
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt log
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt log redirect-next-hop
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-mlt redirect-next-hop
no filter acl ace action <1-2048> <1-2000> { permit | deny } monitor-dst-ports
no filter acl ace action <1-2048> <1-2000> { permit | deny } remark-dscp
no filter acl ace action <1-2048> <1-2000> { permit | deny } redirect-next-hop
no filter acl ace action <1-2048> <1-2000> { permit | deny } remark-dot1p
Specifies the ACE ID.
Specifies the ACL ID.

Note
For each Security ACE, you must define one or more actions as well as the associated action mode (permit or deny). Otherwise, the security ACE cannot be enabled. There is no default configuration for Security ACEs.
With QoS ACEs, the action mode is not configurable. QoS ACEs are always set to action mode permit.
a single slot and port (slot/port)
a range of slots and ports (slot/port-slot/port)
a series of slots and ports (slot/port,slot/port,slot/port)
all ports on the same slot (slot/all)
all ports on the switch (all)
phbcs0
phbcs1
phbaf11
phbaf12
phbaf13
phbcs2
phbaf21
phbaf22
phbaf23
phbcs3
phbaf31
phbaf32
phbaf33
phbcs4
phbaf41
phbaf42
phbaf43
phbcs5
phbef
phbcs6
phbcs7
The default to configure ACE actions to meter flows after a packet matches an ACE is disabled.
Global Configuration