Creating and Applying a Standard IPv4 ACL
Complete the following steps to create a standard ACL.
- Enter
configure terminalto access global configuration mode. - Enter the
ip access-list standardcommand followed by a name or ID number to create the ACL and enter ACL configuration sub-mode. An ID number must be all numeric and be in the range 1 through 99. If you use a name, the name must begin with an alphabetical character and be no more than 47 characters long. - For each rule, enter the deny or permit command followed by needed parameters. As an option, you may specify the sequence number followed by a permit or deny statement. Otherwise, the sequence numbers will be assigned automatically in the order of statement entry in increments of 10.
- Apply the ACL you created to the appropriate interface or VLAN and specify direction. If desired, include the logging enable option to log matched statements that contain the keyword log.
The following example configures an ACL to deny packets from three source IP addresses being received on port 1/1/1. The last rule permits all packets not explicitly denied by the first three ACL entries. (Otherwise, the implicit action is "deny".) In the example, the ACL is applied to the port along with the keywords logging enable. As a result, all deny actions, which include the keyword log, are logged.
device# configure terminal device(config)# ip access-list standard ip_stan_test device(config-std-ipacl_ip_stan_test)# deny host 10.157.22.26 log device(config-std-ipacl_ip_stan_test)# deny 10.157.29.12 log device(config-std-ipacl_ip_stan_test)# deny host IPHost1 log device(config-std-ipacl_ip_stan_test)# permit any device(config-std-ipacl_ip_stan_test)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# ip access-group ip_stan_test in logging enable device(config-if-e1000-1/1/1)# exit device(config)#
The following example is the result of entering
show access-list
all for the previously configured ACL.
device# show access-list all Standard IP access list ip_stan_test: 4 entries 10: deny host 10.157.22.26 log 20: deny host 10.157.29.12 log 30: deny host IPHost1 log 40: permit any
The following example includes remarks preceding each rule. For more information on adding remarks, refer to Adding a Comment for an Entry in an ACL.
device(config)# ip access-list standard 10 device(config-std-ipacl-10)# remark server-lab10-backup device(config-std-ipacl-10)# permit host 192.168.100.14 device(config-std-ipacl-10)# remark clients-lab10 device(config-std-ipacl-10)# permit 192.168.100.0 0.0.0.248 device(config-std-ipacl-10)# exit device(config)#