ACL Rules
To process traffic packets, the traffic needs to be segregated using access-list (ACL) rules. The access lists are used to define the traffic pattern rule to drop, permit, or bypass the traffic pattern. An ACL rule can also be set to log matches in the system log.
Extended ACLs allow you to permit or deny packets based on the following information:
- IP protocol
- Source IP address or host name
- Destination IP address or host name
- Source TCP or UDP port (if the IP protocol is TCP or UDP)
- Destination TCP or UDP port (if the IP protocol is TCP or UDP)
The IP protocol can be one of the following well-known names or any IP protocol number from 0 - 255:
- Internet Control Message Protocol (ICMP)
- Internet Group Management Protocol (IGMP)
- Internet Gateway Routing Protocol (IGRP)
- Internet Protocol (IP)
- Open Shortest Path First (OSPF)
- Transmission Control Protocol (TCP)
- User Datagram Protocol (UDP)
Syntax for ACL Rules
The following syntax is used to define ACL rules.
Syntax: [
no ]
ip access-list{standard|extended}{acl-num|acl-name}
ip access-list command parameters and guidelines
The following parameters are used in the
ip access-list command.
- standard: Creates a standard access control list. Contains rules that permit or deny traffic based on source addresses that you specify. The rules are applicable to all ports of the specified address.
- extended: Contains rules that permit or deny traffic according to source and destination addresses, as well as other parameters. For example, you can also filter by port, protocol (TCP or UDP), and TCP flags.
- acl-num: Specifies the ACL number for a standard or extended access list. The value can be from 1 through 99 for standard IPv4 ACLs and from 100 through 199 for extended IPv4 ACLs.
- acl-name: Specifies a unique IPv4 ACL name. The name can be up to 255 characters, and must begin with an alphabetic character. If the name contains spaces, put it within quotation marks. Otherwise, no special characters are allowed, except for underscores and hyphens.
The following guidelines apply to the
ip access-list
command.
You can also create numbered IPv4 ACLs, using the
access-list command; however, the
ip access-list command is recommended.
An ACL name must be unique among IPv4 and IPv6 standard and extended ACL types.
After you create an IPv4 ACL, enter one or more
permit or
deny commands to create filtering rules for that ACL.
An IPv4 ACL starts functioning only after it is applied to an interface using the
ip access-group command.
The system supports the following IPv4 ACL resources:
- IPv4 numbered standard ACLs: 99
- IPv4 numbered extended ACLs: 100
- IPv4 named standard ACLs: 99
- IPv4 named extended ACLs: 100
- Maximum filter-rules per IPv4 or IPv6 ACL: 2000. You can change the maximum up to
8192 using the
system-max ip-filter-syscommand.
The
no form of the command deletes the ACL. You can delete an IPv4 ACL only after you first
remove it from all interfaces to which it is applied, using the
no ip access-group command.
ACL Examples
The following example provides syntax for applying an ACL to an interface.
device# configure terminal device(config)# interface ethernet < unit/slot/port > device(config int-e-xxx-unit/slot/port)# [no] ip access-group < name | num > [ in | out ]
The following rules form a sample ACL.
10: permit tcp host 18.1.1.3 host 19.1.1.2 log 11: permit tcp host 18.1.1.2 any log 20: permit tcp any host 19.1.1.4 log 30: permit tcp any any eq 1490 log 40: deny tcp host 18.1.1.5 host 19.1.1.5 log 50: deny tcp host 18.1.1.6 any log 60: deny tcp any host 19.1.1.6 log 70: deny tcp any any eq 1590 log 80: permit ip any any log
The following example applies the previously configured ACL called tcp-ex to incoming traffic on port 1/4/4.
device# configure terminal device(config)# interface ethernet 1/4/4 device(config-if-e10000-1/4/4)# ip access-group tcp-ex in
When the traffic starts to flow, it is segregated based on the ACL applied to the interface. When the traffic matches a rule configured for the ACL, a syslog message similar to the following messages is generated.
SYSLOG: <12> Oct 6 19:09:50 device ACL: ACL: List tcp-ex permitted tcp 18.1.1.8(1024)(Ethernet 1/4/4 0010.9400.0002) -> 19.1.1.8(1490), 1 event(s) SYSLOG: <12> Oct 6 19:11:14 device ACL: ACL: List tcp-ex denied tcp 18.1.1.5(1024)(Ethernet 1/4/4 0010.9400.0002) -> 19.1.1.5(1024), 1 event(s)
ACLs can also be defined for IPv6 traffic as shown in the following example.
device(config)# ipv6 access-list ipv6_test device(config-ipv6-access-list ipv6_test)# deny tcp host 2001:DB8:e0bb::2 any eq telnet log device(config-ipv6-access-list ipv6_test)# permit ipv6 any any log device(config-ipv6-access-list ipv6_test)# exit
Access an interface on which you need to apply the ACL.
device(config)# interface ethernet 1/1/1
If needed, enable IPv6 on that interface.
device(config-if-e1000-1/1/1)# ipv6 enable
The following example applies the previously configured ACL access group called ipv6_test to outgoing traffic on port 1/1/1.
device(config-if-e1000-1/1/1)# ipv6 access-group ipv6_test out