sequence (permit | deny in Standard IPv4 ACLs)

Inserts filtering rules in IPv4 standard named or numbered ACLs. Standard ACLs permit or deny traffic according to source address only.
Syntax
sequence seq-num { deny | permit } { S_IPaddress [ mask ] | host S_IPaddress | any } [ log ] [ mirror ]
{ deny | permit } { S_IPaddress [ mask ] | host S_IPaddress | any } [ log ] [ mirror ]
no sequence seq-num
no sequence { deny | permit } { S_IPaddress [ mask ] | host S_IPaddress | any } [ log ] [ mirror ]
Parameters
sequence
(Optional) Enables you to assign a sequence number to the rule.
seq-num
Valid values range from 1 through 65000.
deny
Specifies rules to deny traffic.
permit
Specifies rules to permit traffic.
S_IPaddress
Specifies a source address for which you want to filter the subnet.
mask
Defines a subnet mask that includes the source address you specified.
host
Indicates the source IP address is a host address.
S_IPaddress
Specifies source address.
any
Specifies all source addresses.
log
Enables logging for the rule.
mirror
Mirrors packets matching the rule.
Modes

IPv4 ACL configuration mode

IPv6 ACL configuration mode

Usage Guidelines

This command configures rules to permit or drop traffic based on source addresses. You can also enable logging and mirroring.

The order of the rules in an ACL is critical, as the first matching rule stops further processing. When creating rules, specifying sequence values determines the order of rule processing. If you do not specify a sequence value, the rule is added to the end of the list. Such a rule is automatically assigned the next multiple of 10 as a sequence number.

You can specify a mask in either of the following ways:

  • Wildcard mask format. The advantage of this format is that it enables you to mask any bit, for example by specifying 0.255.0.255.
  • Classless Interdomain Routing (CIDR) format—in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.

On RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.

For the log keyword to trigger a log entry, logging must be enabled with the logging enable command.

To delete a rule from an ACL, do either of the following:

  • Enter no sequence seq-value.
  • Type no followed by the full command syntax without sequence seq-value.

Examples

The following example shows how to configure a standard numbered ACL and apply it to incoming traffic on port 1/1/1.

device# configure terminal
device(config)# ip access-list standard 1 
device(config-std-ipacl-1)# sequence 10 deny host 10.157.22.26 log
device(config-std-ipacl-1)# sequence 20 deny 10.157.29.12 log
device(config-std-ipacl-1)# sequence 30 deny host IPHost1 log
device(config-std-ipacl-1)# sequence 40 permit any
device(config-std-ipacl-1)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ip access-group 1 in
History
Release version Command history
08.0.50 This command was modified to support the sequence keyword and to support logging in permit rules.