Creating and Applying an Extended IPv4 ACL
Complete the following steps to create an extended IPv4 ACL.
- Enter
configure terminalto access global configuration mode. - Enter the
ip access-list extendedcommand followed by a name or ID to create the ACL and enter ACL configuration sub-mode. An ID number must be all numeric and be in the range 100 through 199. If you use a name, it must begin with an alphabetical character and contain no more than 47 characters. - For each rule, enter the permit or deny command, specifying the needed parameters. As an option, you can specify a sequence number followed by a permit or deny statement. Otherwise, the sequence numbers will be assigned automatically in the order of statement entry in increments of 10.
- Apply the ACL you created to the
needed interfaces or VLANs using the
ip access-groupcommand and specify the direction. If desired, include the logging enable option to log matched statements that contain the keyword log.
The following example includes remarks preceding each rule.
device# configure terminal device(config)# ip access-list extended ip_ext_test device(config-ext-ipacl-ip_ext_test)# remark Permits ICMP traffic from 10.157.22.x to 10.157.21.x: device(config-ext-ipacl-ip_ext_test)# permit icmp 10.157.22.0/24 10.157.21.0/24 device(config-ext-ipacl-ip_ext_test)# remark Denies IGMP traffic from "rkwong" to 10.157.21.x: device(config-ext-ipacl-ip_ext_test)# deny igmp host rkwong 10.157.21.0/24 log device(config-ext-ipacl-ip_ext_test)# remark Denies IGRP traffic from "rkwong" to 10.157.21.x: device(config-ext-ipacl-ip_ext_test)# deny igrp 10.157.21.0/24 host rkwong log device(config-ext-ipacl-ip_ext_test)# remark Denies IPv4 traffic from 10.157.21.100 to 10.157.22.1, with logging: device(config-ext-ipacl-ip_ext_test)# deny ip host 10.157.21.100 host 10.157.22.1 log device(config-ext-ipacl-ip_ext_test)# remark Denies all OSPF traffic, with logging: device(config-ext-ipacl-ip_ext_test)# deny ospf any any log device(config-ext-ipacl-ip_ext_test)# remark Permits traffic not explicitly denied by the previous rules: device(config-ext-ipacl-ip_ext_test)# permit ip any any