ip access-list
ip access-list
{
standard
|
extended
}
{
acl-name
|
acl-id
}no ip access-list
{
standard
|
extended
}
{
acl-name
|
acl-id
}No IPv4 ACLs are defined.
- standard
- Creates a standard access control list. Contains rules that permit or deny traffic based on source addresses that you specify. The rules are applicable to all ports of the specified address.
- extended
- Contains rules that permit or deny traffic according to source and destination addresses, as well as other parameters. For example, you can also filter by port, protocol (TCP or UDP), and TCP flags.
- acl-name
- Specifies a unique IPv4 ACL name. The name can be up to 255 characters, and must begin with an alphabetic character. If the name contains spaces, put it within quotation marks. Otherwise, no special characters are allowed, except for underscores and hyphens.
Global configuration mode
The
no form of the command deletes the ACL. You can delete an IPv4 ACL only after you first
remove it from all interfaces to which it is applied, using the
no ip access-group command.
From FastIron release 08.0.80, you cannot create
IPv4 ACLs using the access-list command. You must use the ip
access-list command instead.
An ACL name must be unique among IPv4 and IPv6 standard and extended ACL types.
The following points apply to naming ACLs:
- An ACL name must begin with an alphabetical character followed by alphanumeric characters.
- The maximum length of an ACL name is 47 characters.
- An ACL name cannot contain special characters.
- The ACL name cannot be 'test'.
After you create an IPv4 ACL, enter one or more
permit or
deny commands to create filtering rules for that ACL.
An IPv4 ACL starts functioning only after it is applied to an interface using the
ip access-group command.
The system supports the following IPv4 ACL resources:
- IPv4 named standard ACLs: 99
- IPv4 named extended ACLs: 100
- Maximum filter-rules per IPv4 or IPv6 ACL: 2048. You can increase the maximum from
2048 through 8192 using the
system-max ip-filter-syscommand.
The wildcard mask is in dotted-decimal notation (IP address format). It is a four-part value, where each part is 8 bits (one byte) separated by dots, and each bit is a one or a zero. Each part is a number ranging from 0 to 255, for example, 0.0.0.255. Zeros in the mask mean the packet source address must match the source IP address. Ones mean any value matches. For example, the source IP address and wildcard values 10.157.22.26 0.0.0.255 mean that all hosts in the Class C subnet 10.157.22.x match the policy.
If you prefer to specify the wildcard (mask value) in CIDR format, you can enter a forward slash (/) after the IP address and then enter the number of significant bits in the mask. For example, you can enter the CIDR equivalent of 10.157.22.26 0.0.0.255 as 10.157.22.26/24. The CLI automatically converts the CIDR number into the appropriate ACL mask (where zeros instead of ones are the significant bits) and changes the non-significant bits of the IP address into ones. For example, if you specify 10.157.22.26/24 or 10.157.22.26 0.0.0.255 and then save the changes to the startup-config file, the value appears as 10.157.22.0/24 (if you have enabled display of subnet lengths) or 10.157.22.0 0.0.0.255 in the startup-config file.
If you enable the software to display IP subnet masks in CIDR format, the mask is
saved in the file in "/mask-bits" format. To enable the software to display the CIDR
masks, enter the
ip show-subnet-length command at the global configuration level of the CLI. You can use the CIDR format
to configure the ACL entry regardless of whether the software is configured to display
the masks in CIDR format.
In extended IPv4 access-lists, the following protocols can be matched in permit or deny statements:
In extended IPv4 access-lists, the following TCP/UDP application port names are allowed, in addition to any application-specific port number in decimal format:
The following example configures a standard ACL.
device# configure terminal device(config)# ip access-list standard acl1 device(config-std-ipacl-acl1)#
The following example configures a standard ACL to deny packets from three source IP addresses being received on port 1/1/1. The last rule permits all packets not explicitly denied by the first three ACL entries. (Otherwise, the implicit action is "deny".) In the example, ACL is applied to the port along with the keywords logging enable. As a result, all deny actions, which include the keyword log, are logged.
device# configure terminal device(config)# ip access-list standard ip_stan_test device(config-std-ipacl-ip_stan_test)# deny host 10.157.22.26 log device(config-std-ipacl-ip_stan_test)# deny 10.157.29.12 log device(config-std-ipacl-ip_stan_test)# deny host IPHost1 log device(config-std-ipacl-ip_stan_test)# permit any device(config-std-ipacl-ip_stan_test)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# ip access-group ip_stan_test in logging enable device(config-if-e1000-1/1/1)# exit device(config)#
The following example deletes an IPv4 ACL.
device# configure terminal device(config)# no ip access-list standard acl1
The following example creates an extended ACL and enters ACL configuration sub-mode, where filters can be defined.
device# configure terminal device(config)# ip access-list extended acl125 device(config-ext-ipacl-acl125)#
The following example creates an extended, named IPv4 ACL and defines rules for it.
device# configure terminal device(config)# ip access-list extended acl101 device(config-ext-ipacl-acl101)# deny udp 19.1.2.0 0.0.0.255 eq 2023 20.1.2.0 0.0.0.255 eq 2025 dscp-mapping 23 device(config-ext-ipacl-acl101)# permit 12 host 098.096.31.10 any device(config-ext-ipacl-acl101)# deny tcp host 098.092.12.10 131.21.12.0/24 syn device(config-ext-ipacl-acl101)# deny 120 host 18.192.112.110 13.2.2.0/24 log device(config-ext-ipacl-acl101)# permit ip any any
The following example creates an extended, named IPv4 ACL, defines rules in it, and applies it to inbound traffic on an Ethernet interface.
device(config)# ip access-list extended blocktelnet device(config-ext-ipacl-blocktelnet)# deny tcp host 10.157.22.26 any eq telnet device(config-ext-ipacl-blocktelnet)# permit ip any any device(config-ext-ipacl-blocktelnet)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# ip access-group blocktelnet in
The following example creates an IP extended ACL that includes remarks preceding each rule.
device# configure terminal device(config)# ip access-list extended acl22 device(config-ext-ipacl-acl22)# remark Permits ICMP traffic from 10.157.22.x to 10.157.21.x: device(config-ext-ipacl-acl22)# permit icmp 10.157.22.0/24 10.157.21.0/24 device(config-ext-ipacl-acl22)# remark Denies IGMP traffic from "rkwong" to 10.157.21.x: device(config-ext-ipacl-acl22)# deny igmp host rkwong 10.157.21.0/24 log device(config-ext-ipacl-acl22)# remark Denies IGRP traffic from "rkwong" to 10.157.21.x: device(config-ext-ipacl-acl22)# deny igrp 10.157.21.0/24 host rkwong log device(config-ext-ipacl-acl22)# remark Denies IPv4 traffic from 10.157.21.100 to 10.157.22.1, with logging: device(config-ext-ipacl-acl22)# deny ip host 10.157.21.100 host 10.157.22.1 log device(config-ext-ipacl-acl22)# remark Denies all OSPF traffic, with logging: device(config-ext-ipacl-acl22)# deny ospf any any log device(config-ext-ipacl-acl22)# remark Permits traffic not explicitly denied by the previous rules: device(config-ext-ipacl-acl22)# permit ip any any
| Release version | Command history |
|---|---|
| 08.0.95 | This command was modified to use names no longer than 47 characters and to remove explicit sequence number requirements. |