Filtering on IP Precedence and ToS Values

The following example configures an extended IP ACL that matches based on IP precedence.
device(config)# ip access-list extended acl103
device(config-ext-ipacl-acl103)# deny tcp 10.157.21.0/24 10.157.22.0/24 precedence internet
device(config-ext-ipacl-acl103)# deny tcp 10.157.21.0/24 eq ftp 10.157.22.0/24 precedence 6
device(config-ext-ipacl-acl103)# permit ip any any 

The first entry in this ACL denies TCP traffic from the 10.157.21.x network to the 10.157.22.x network if the traffic has the IP precedence option "internet" (equivalent to "6").

The second entry denies all FTP traffic from the 10.157.21.x network to the 10.157.22.x network if the traffic has the IP precedence value "6" (equivalent to "internet").

The third entry permits all packets that are not explicitly denied by the other entries. Without this entry, the ACL would deny all incoming or outgoing IP traffic on the ports to which you assign the ACL.

The following example configures an IP ACL that matches based on ToS.

device(config)# ip access-list extended acl104 
device(config-ext-ipacl-acl104)# deny tcp 10.157.21.0/24 10.157.22.0/24 tos normal
device(config-ext-ipacl-acl104)# deny tcp 10.157.21.0/24 eq ftp 10.157.22.0/24 tos 13
device(config-ext-ipacl-acl104)# permit ip any any 

The first entry in this IP ACL denies TCP traffic from the 10.157.21.x network to the 10.157.22.x network if the traffic has the IP ToS option "normal" (equivalent to "0").

The second entry denies all FTP traffic from the 10.157.21.x network to the 10.157.22.x network if the traffic has the IP ToS value "13" (equivalent to "max-throughput", "min-delay", and "min-monetary-cost").

The third entry permits all packets that are not explicitly denied by the other entries. Without this entry, the ACL would deny all incoming or outgoing IP traffic on the ports to which you assign the ACL.