ACL Rules

To process traffic packets, the traffic needs to be segregated using access-list (ACL) rules. The access lists are used to define the traffic pattern rule to drop, permit, or bypass the traffic pattern. An ACL rule can also be set to log matches in the system log.

Note: The administrator is expected to configure a default deny rule as the final ACL rule on all interfaces to ensure that the encrypted device rejects traffic that is not explicitly allowed by earlier rules.

Extended ACLs allow you to permit or deny packets based on the following information:

  • IP protocol
  • Source IP address or host name
  • Destination IP address or host name
  • Source TCP or UDP port (if the IP protocol is TCP or UDP)
  • Destination TCP or UDP port (if the IP protocol is TCP or UDP)

The IP protocol can be one of the following well-known names or any IP protocol number from 0 - 255:

  • Internet Control Message Protocol (ICMP)
  • Internet Group Management Protocol (IGMP)
  • Internet Gateway Routing Protocol (IGRP)
  • Internet Protocol (IP)
  • Open Shortest Path First (OSPF)
  • Transmission Control Protocol (TCP)
  • User Datagram Protocol (UDP)

Syntax for ACL Rules

The following syntax is used to define ACL rules.

Syntax: [ no ] ip access-list{standard|extended}{acl-num|acl-name}

ip access-list command parameters and guidelines

The following parameters are used in the ip access-list command.

  • standard: Creates a standard access control list. Contains rules that permit or deny traffic based on source addresses that you specify. The rules are applicable to all ports of the specified address.
  • extended: Contains rules that permit or deny traffic according to source and destination addresses, as well as other parameters. For example, you can also filter by port, protocol (TCP or UDP), and TCP flags.
  • acl-num: Specifies the ACL number for a standard or extended access list. The value can be from 1 through 99 for standard IPv4 ACLs and from 100 through 199 for extended IPv4 ACLs.
  • acl-name: Specifies a unique IPv4 ACL name. The name can be up to 255 characters, and must begin with an alphabetic character. If the name contains spaces, put it within quotation marks. Otherwise, no special characters are allowed, except for underscores and hyphens.

The following guidelines apply to the ip access-list command.

You can also create numbered IPv4 ACLs, using the access-list command; however, the ip access-list command is recommended.

An ACL name must be unique among IPv4 and IPv6 standard and extended ACL types.

After you create an IPv4 ACL, enter one or more permit or deny commands to create filtering rules for that ACL.

An IPv4 ACL starts functioning only after it is applied to an interface using the ip access-group command.

The system supports the following IPv4 ACL resources:

  • IPv4 numbered standard ACLs: 99
  • IPv4 numbered extended ACLs: 100
  • IPv4 named standard ACLs: 99
  • IPv4 named extended ACLs: 100
  • Maximum filter-rules per IPv4 or IPv6 ACL: 2000. You can change the maximum up to 8192 using the system-max ip-filter-sys command.

The no form of the command deletes the ACL. You can delete an IPv4 ACL only after you first remove it from all interfaces to which it is applied, using the no ip access-group command.

ACL Examples

The following example provides syntax for applying an ACL to an interface.

 
device# configure terminal
device(config)# interface ethernet < unit/slot/port >
device(config int-e-xxx-unit/slot/port)# [no] ip access-group < name | num > [ in | out ]

The following rules form a sample ACL.

10: permit tcp host 18.1.1.3 host 19.1.1.2 log
11: permit tcp host 18.1.1.2 any log
20: permit tcp any host 19.1.1.4 log
30: permit tcp any any eq 1490 log
40: deny tcp host 18.1.1.5 host 19.1.1.5 log
50: deny tcp host 18.1.1.6 any log
60: deny tcp any host 19.1.1.6 log
70: deny tcp any any eq 1590 log
80: permit ip any any log

The following example applies the previously configured ACL called tcp-ex to incoming traffic on port 1/4/4.

device# configure terminal
device(config)# interface ethernet 1/4/4
device(config-if-e10000-1/4/4)# ip access-group tcp-ex in

When the traffic starts to flow, it is segregated based on the ACL applied to the interface. When the traffic matches a rule configured for the ACL, a syslog message similar to the following messages is generated.

SYSLOG: <12> Oct  6 19:09:50 device ACL: ACL: List tcp-ex permitted tcp 18.1.1.8(1024)(Ethernet 1/4/4 0010.9400.0002) 
-> 19.1.1.8(1490), 1 event(s)

SYSLOG: <12> Oct  6 19:11:14 device ACL: ACL: List tcp-ex denied tcp 18.1.1.5(1024)(Ethernet 1/4/4 0010.9400.0002) 
-> 19.1.1.5(1024), 1 event(s)

ACLs can also be defined for IPv6 traffic as shown in the following example.

device(config)# ipv6 access-list ipv6_test
device(config-ipv6-access-list ipv6_test)# deny tcp host 2001:DB8:e0bb::2 any eq telnet log
device(config-ipv6-access-list ipv6_test)# permit ipv6 any any log
device(config-ipv6-access-list ipv6_test)# exit

Access an interface on which you need to apply the ACL.

device(config)# interface ethernet 1/1/1

If needed, enable IPv6 on that interface.

device(config-if-e1000-1/1/1)# ipv6 enable

The following example applies the previously configured ACL access group called ipv6_test to outgoing traffic on port 1/1/1.

device(config-if-e1000-1/1/1)# ipv6 access-group ipv6_test out