ip access-list

Creates a named IPv4 standard or extended access control list (ACL) that permits or denies network traffic based on criteria that you specify.
Syntax
ip access-list { standard | extended } { acl-name | acl-id }
no ip access-list { standard | extended } { acl-name | acl-id }
Command Default

No IPv4 ACLs are defined.

Parameters
standard
Creates a standard access control list. Contains rules that permit or deny traffic based on source addresses that you specify. The rules are applicable to all ports of the specified address.
extended
Contains rules that permit or deny traffic according to source and destination addresses, as well as other parameters. For example, you can also filter by port, protocol (TCP or UDP), and TCP flags.
acl-name
Specifies a unique IPv4 ACL name. The name can be up to 255 characters, and must begin with an alphabetic character. If the name contains spaces, put it within quotation marks. Otherwise, no special characters are allowed, except for underscores and hyphens.
acl-id
Specifies the ACL number for a standard or extended access list. The value can be from 1 through 99 for standard IPv4 ACLs and from 100 through 199 for extended IPv4 ACLs.
Modes

Global configuration mode

Usage Guidelines

The no form of the command deletes the ACL. You can delete an IPv4 ACL only after you first remove it from all interfaces to which it is applied, using the no ip access-group command.

From FastIron release 08.0.80, you cannot create IPv4 ACLs using the access-list command. You must use the ip access-list command instead.

An ACL name must be unique among IPv4 and IPv6 standard and extended ACL types.

The following points apply to naming ACLs:

  • An ACL name must begin with an alphabetical character followed by alphanumeric characters.
  • The maximum length of an ACL name is 47 characters.
  • An ACL name cannot contain special characters.
  • The ACL name cannot be 'test'.

After you create an IPv4 ACL, enter one or more permit or deny commands to create filtering rules for that ACL.

An IPv4 ACL starts functioning only after it is applied to an interface using the ip access-group command.

The system supports the following IPv4 ACL resources:

  • IPv4 named standard ACLs: 99
  • IPv4 named extended ACLs: 100
  • Maximum filter-rules per IPv4 or IPv6 ACL: 2048. You can increase the maximum from 2048 through 8192 using the system-max ip-filter-sys command.

The wildcard mask is in dotted-decimal notation (IP address format). It is a four-part value, where each part is 8 bits (one byte) separated by dots, and each bit is a one or a zero. Each part is a number ranging from 0 to 255, for example, 0.0.0.255. Zeros in the mask mean the packet source address must match the source IP address. Ones mean any value matches. For example, the source IP address and wildcard values 10.157.22.26 0.0.0.255 mean that all hosts in the Class C subnet 10.157.22.x match the policy.

If you prefer to specify the wildcard (mask value) in CIDR format, you can enter a forward slash (/) after the IP address and then enter the number of significant bits in the mask. For example, you can enter the CIDR equivalent of 10.157.22.26 0.0.0.255 as 10.157.22.26/24. The CLI automatically converts the CIDR number into the appropriate ACL mask (where zeros instead of ones are the significant bits) and changes the non-significant bits of the IP address into ones. For example, if you specify 10.157.22.26/24 or 10.157.22.26 0.0.0.255 and then save the changes to the startup-config file, the value appears as 10.157.22.0/24 (if you have enabled display of subnet lengths) or 10.157.22.0 0.0.0.255 in the startup-config file.

If you enable the software to display IP subnet masks in CIDR format, the mask is saved in the file in "/mask-bits" format. To enable the software to display the CIDR masks, enter the ip show-subnet-length command at the global configuration level of the CLI. You can use the CIDR format to configure the ACL entry regardless of whether the software is configured to display the masks in CIDR format.

In extended IPv4 access-lists, the following protocols can be matched in permit or deny statements:

  • esp
  • gre
  • icmp
  • igmp
  • ip
  • ipv6
  • ospf
  • pim
  • rsvp
  • tcp
  • udp

In extended IPv4 access-lists, the following TCP/UDP application port names are allowed, in addition to any application-specific port number in decimal format:

  • ftp-data
  • ftp
  • ssh
  • telnet
  • smtp
  • dns
  • http
  • gppitnp
  • pop2
  • pop3
  • sftp
  • sqlserv
  • bgp
  • ldap
  • ssl

Examples

The following example configures a standard ACL.

device# configure terminal
device(config)# ip access-list standard acl1
device(config-std-ipacl-acl1)#

The following example configures a standard ACL to deny packets from three source IP addresses being received on port 1/1/1. The last rule permits all packets not explicitly denied by the first three ACL entries. (Otherwise, the implicit action is "deny".) In the example, ACL is applied to the port along with the keywords logging enable. As a result, all deny actions, which include the keyword log, are logged.

device# configure terminal
device(config)# ip access-list standard ip_stan_test
device(config-std-ipacl-ip_stan_test)# deny host 10.157.22.26 log
device(config-std-ipacl-ip_stan_test)# deny 10.157.29.12 log
device(config-std-ipacl-ip_stan_test)# deny host IPHost1 log
device(config-std-ipacl-ip_stan_test)# permit any
device(config-std-ipacl-ip_stan_test)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ip access-group ip_stan_test in logging enable
device(config-if-e1000-1/1/1)# exit
device(config)#

The following example deletes an IPv4 ACL.

device# configure terminal
device(config)# no ip access-list standard acl1

The following example creates an extended ACL and enters ACL configuration sub-mode, where filters can be defined.

device# configure terminal
device(config)# ip access-list extended acl125
device(config-ext-ipacl-acl125)#

The following example creates an extended, named IPv4 ACL and defines rules for it.

device# configure terminal
device(config)# ip access-list extended acl101
device(config-ext-ipacl-acl101)# deny udp 19.1.2.0 0.0.0.255 eq 2023 20.1.2.0 0.0.0.255 eq 2025 dscp-mapping 23
device(config-ext-ipacl-acl101)# permit 12 host 098.096.31.10 any
device(config-ext-ipacl-acl101)# deny tcp  host 098.092.12.10 131.21.12.0/24 syn
device(config-ext-ipacl-acl101)# deny 120  host 18.192.112.110 13.2.2.0/24 log
device(config-ext-ipacl-acl101)# permit ip any any

The following example creates an extended, named IPv4 ACL, defines rules in it, and applies it to inbound traffic on an Ethernet interface.

device(config)# ip access-list extended blocktelnet
device(config-ext-ipacl-blocktelnet)# deny tcp host 10.157.22.26 any eq telnet
device(config-ext-ipacl-blocktelnet)# permit ip any any
device(config-ext-ipacl-blocktelnet)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# ip access-group blocktelnet in

The following example creates an IP extended ACL that includes remarks preceding each rule.

device# configure terminal
device(config)# ip access-list extended acl22
device(config-ext-ipacl-acl22)# remark Permits ICMP traffic from 10.157.22.x to 10.157.21.x:
device(config-ext-ipacl-acl22)# permit icmp 10.157.22.0/24 10.157.21.0/24
device(config-ext-ipacl-acl22)# remark Denies IGMP traffic from "rkwong" to 10.157.21.x:
device(config-ext-ipacl-acl22)# deny igmp host rkwong 10.157.21.0/24 log
device(config-ext-ipacl-acl22)# remark Denies IGRP traffic from "rkwong" to 10.157.21.x:
device(config-ext-ipacl-acl22)# deny igrp 10.157.21.0/24 host rkwong log
device(config-ext-ipacl-acl22)# remark Denies IPv4 traffic from 10.157.21.100 to 10.157.22.1, with logging:
device(config-ext-ipacl-acl22)# deny ip host 10.157.21.100 host 10.157.22.1 log
device(config-ext-ipacl-acl22)# remark Denies all OSPF traffic, with logging:
device(config-ext-ipacl-acl22)# deny ospf any any log
device(config-ext-ipacl-acl22)# remark Permits traffic not explicitly denied by the previous rules:
device(config-ext-ipacl-acl22)# permit ip any any
History
Release version Command history
08.0.95 This command was modified to use names no longer than 47 characters and to remove explicit sequence number requirements.