permit (Standard IPv4 ACLs)

Inserts filtering rules in IPv4 standard named or numbered ACLs that will permit packets.
Syntax
permit { Source_IPaddress [ mask ] | host { hostname | Source_IPaddress [ mask ] } | any } [ log ] [ mirror ]
no permit{ Source_IPaddress [ mask ] | host {hostname | Source_IPaddress [ mask ] } | any } [ log ] [ mirror ]
Parameters
Source_IPaddress
Specifies a source address for which you want to filter the subnet.
mask
Defines a subnet mask to be applied to the source address you specified.
host
Indicates the source IP address is a host address.
hostname
Specifies the known hostname associated with a particular source IP address.
Source_IPaddress
Specifies the souce IP address of the host.
any
Specifies all source addresses.
log
Enables logging for the rule.
mirror
Mirrors packets matching the rule.
Modes

IPv4 ACL configuration mode

Usage Guidelines

This command configures rules to permit traffic based on source addresses. You can also enable logging and mirroring.

Standard ACLs permit traffic according to source address only.

The order of the rules in an ACL is critical, as the first matching rule stops further processing. When creating rules, specifying sequence values determines the order of rule processing. If you do not specify a sequence value, the rule is added to the end of the list. Such a rule is automatically assigned the next multiple of 10 as a sequence number.

You can specify a mask in either of the following ways:

  • Wildcard mask format. The advantage of this format is that it enables you to mask any bit, for example by specifying 0.255.0.255.
  • Classless Interdomain Routing (CIDR) format—in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.

For RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.

For the log keyword to trigger a log entry, logging must be enabled with the logging enable command.

To delete a rule from an ACL, use the no permit command followed by the full command syntax.

Examples

The following example shows how to configure a standard numbered ACL and apply it to incoming traffic on port 1/1/1.

device# configure terminal
device(config)# ip access-list standard 11 
device(config-std-ipacl-11)# deny host 10.157.22.26 log
device(config-std-ipacl-11)# deny 10.157.29.12 log
device(config-std-ipacl-11)# deny host IPHost1 log
device(config-std-ipacl-11)# permit any
device(config-std-ipacl-11)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ip access-group 11 in