Preserving User Input for ACL TCP/UDP Port Numbers

ACL implementations automatically display the TCP/UDP port name instead of the port number, regardless of user preference, unless the device is configured to preserve user input. When the option to preserve user input is enabled, the system displays either the port name or the number.

To preserve user input, enter the ip preserve-ACL-user-input-format command.

device(config)# ip preserve-ACL-user-input-format

The following example shows how this to preserve user input for a TCP port (and it works the same way for UDP ports). In this example, the user identifies the TCP port by number (80) when configuring ACL group acl140. However, the show ip access-lists acl140 output reverts to the port name for the TCP port ('http' in this example). After the user enters the ip preserve-ACL-user-input-format command, the show ip access-lists acl140 output displays either the TCP port number or name, depending on how it was configured by the user.

device(config)# ip access-list extended acl140 
device(config-ext-ipacl-acl140)# permit tcp any any eq 80
device(config-ext-ipacl-acl140)# permit tcp any any eq ftp
device(config-ext-ipacl-acl140)# show ip access-lists acl140
Extended IP access list acl140
permit tcp any any eq http
permit tcp any any eq ftp
device(config-ext-ipacl-acl140)# permit tcp any any eq 80
device(config-ext-ipacl-acl140)# permit tcp any any eq ftp
device(config-ext-ipacl-acl140)# show ip access-lists acl140
Extended IP access list acl140
permit tcp any any eq http
permit tcp any any eq ftp
device(config-ext-ipacl-acl140)# ip preserve-ACL-user-input-format
device(config-ext-ipacl-acl140)# show ip access-lists acl140
Extended IP access list acl140
permit tcp any any eq 80
permit tcp any any eq ftp