sequence (permit | deny in Extended IPv4 ACLs)

Inserts filtering rules in IPv4 extended named or numbered ACLs.
Syntax

Use the following syntax to define a TCP or UDP rule:

[sequence seq-num ] { deny | permit } { tcp | udp } { S_IPaddress [ mask ] | host S_IPaddress | any } [ source-comparison-operators ] { D_IPaddress [ mask ] | host D_IPaddress | any } [ established ] [ destination-comparison-operators ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax to define an ICMP rule:

[ sequence seq-num ] { deny | permit } icmp { S_IPaddress [ mask ] | host S_IPaddress | any } { D_IPaddress [ mask ] | host D_IPaddress | any } [ icmp-num | icmp-type ] [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]

Use the following syntax to define a rule for protocols other than TCP, UDP, or ICMP:

[ sequence seq-num ] { deny | permit } ip-protocol { S_IPaddress[mask]|hostS_IPaddress | any } { D_IPaddress [ mask ] | host D_IPaddress | any } [ precedence { precedence-name | precedence-value } ] [ tos { tos-name | tos-value } ] [ dscp-matching dscp-value ] [ dscp-marking dscp-value ] [ 802.1p-priority-matching 802.1p-value ] [ 802.1p-priority-marking 802.1p-value ] [ internal-priority-marking queuing-priority ] [ 802.1p-and-internal-marking priority-value ] [ traffic-policy name ] [ log ] [ mirror ]
no sequence seq-num
Parameters
sequence
(Optional) Enables you to assign a sequence number to the rule.
seq-num
Valid values range from 1 through 65000.
deny
Specifies rules to deny traffic.
permit
Specifies rules to permit traffic.
ip-protocol
Specifies the type of IPv4 packet to filter. You can either specify a protocol number (from 0 through 255) or a supported protocol name. For a complete list of protocols, type ? after permit or deny. Supported protocols include:
  • icmp—Internet Control Message Protocol
  • igmp—Internet Group Management Protocol
  • igrp—Internet Gateway Routing Protocol
  • ip—any IPv4 protocol
  • ospf—Open Shortest Path First
  • tcp—Transmission Control Protocol
  • udp—User Datagram Protocol
S_IPaddress
Specifies a source address for which you want to filter the subnet.
mask
Defines a mask, whose effect is to specify a subnet that includes the source address that you specified. For options to specify the mask, see the Usage Guidelines.
host
Specifies the source as a host.
S_IPaddress
Specifies the source address of the host.
any
Specifies all source addresses.
source-comparison-operators and destination-comparison-operators
If you specified tcp or udp, the following optional operators are available:
eq
Specifies the address is equal to the port name or number you enter after eq.
gt
Specifies port numbers that are equal to or greater than the port number or that are equal to or greater than the numeric equivalent of the port name you enter after gt.
lt
Specifies port numbers that are equal to or less than the port number or that are equal to or less than the numeric equivalent of the port name you enter after lt.
neq
Specifies all port numbers except the port number or port name you enter after neq.
range
Specifies all port numbers that are between the first port name or number and the second name or number you enter following the range keyword. Enter the range as two values separated by a space. The first port number in the range must be less than the last number in the range. For example, to apply the policy to all ports between and including 23 (Telnet) and 53 (DNS), enter the following: 23 53 .
D_IPaddress
Specifies a destination address for which you want to filter the subnet.
mask
Defines a subnet mask that includes the destination address that you specified. For mask options, refer to the Usage Guidelines.
host
Specifies a host as destination.
D_IPaddress
Specifies the destination address of the host.
any
Specifies all destination addresses.
established
(For TCP rules only) Filter packets that have the Acknowledgment (ACK) or Reset (RST) flag set. This policy applies only to established TCP sessions, not to new sessions.
icmp-num | icmp-type
(For ICMP only) Specifies a named or numbered message type.
icmp-num
Specifies a numbered message type. Use this format if the rule also needs to include precedence, tos , one of the DSCP options, one of the 802.1p options, internal-priority-marking , or traffic-policy.
any-icmp-type
Specifies any ICMP type.
echo
Specifies an echo request (ping).
echo-reply
Specifies an echo reply.
information-request
Specifies an information request.
mask-reply
Specifies an address mask reply.
mask-request
Specifies an address mask request.
parameter-problem
Specifies a parameter problem.
redirect
Specifies a redirect message.
source-quench
Specifies a relieve congestion message.
time-exceeded
Specifies a time exceeded message.
timestamp-reply
Specifies a timestamp reply.
timestamp-request
Specifies a timestamp request.
unreachable
Specifies a destination-unreachable message.
precedence { precedence-name | precedence-value }
Specifies a precedence-name or corresponding precedence-value, as follows:
0 or routine
Specifies routine precedence.
1 or priority
Specifies priority precedence.
2 or immediate
Specifies immediate precedence.
3 or flash
Specifies flash precedence.
4 or flash-override
Specifies flash-override precedence.
5 or critical
Specifies critical precedence.
6 or internet
Specifies internetwork control precedence.
7 or network
Specifies network control precedence.
tos { tos-name | tos-value }
Specifies a type of service (ToS). Enter either a supported tos-name or the equivalent tos-value.
0 or normal
Specifies normal ToS.
1 or min-monetary-cost
Specifies min monetary cost ToS.
2 or max-reliability
Specifies max reliability ToS.
4 or max-throughput
Specifies max throughput ToS.
8 or min-delay
Specifies min-delay ToS.
dscp-matching dscp-value
Filters by DSCP value. Values range from 0 through 63.
dscp-marking dscp-value
Assigns the DSCP value that you specify to the packet. Values range from 0 through 63.
802.1p-priority-matching 802.1p-value
Filters by 802.1p priority, for rate limiting. Values range from 0 through 7.
802.1p-priority-marking 802.1p-value
Assigns the 802.1p value that you specify to the packet. Values range from 0 through 7.
internal-priority-marking queuing-priority
Assigns the internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
802.1p-and-internal-marking priority-value
Assigns the identical 802.1p value and internal queuing priority (traffic class) that you specify to the packet. Values range from 0 through 7.
traffic-policy name
Enables the device to limit the rate of inbound traffic and to count the packets and bytes per packet to which ACL permit or deny clauses are applied. For configuration procedures and examples, refer to the chapter "Traffic Policies" in the RUCKUS FastIron Traffic Management Configuration Guide.
log
Enables SNMP traps and Syslog messages for the rule. In addition, logging must be enabled using the logging enable command.
mirror
Mirrors packets matching the rule.
Modes

IPv4 ACL configuration mode

IPv6 ACL configuration mode

Usage Guidelines

Extended ACLs permit or deny traffic according to source and destination addresses, port protocol, and other IPv4 frame content. You can also enable logging and mirroring.

The order of the rules in an ACL is critical, as the first matching rule stops further processing. When creating rules, specifying sequence values determines the order of rule processing. If you do not specify a sequence value, the rule is added to the end of the list. Such a rule is automatically assigned the next multiple of 10 as a sequence number.

You can specify a mask in either of the following ways:

  • Wildcard mask format (for example, 0.0.0.255). The advantage of this format is that it enables you mask any bit, for example by specifying 0.255.0.255.
  • Classless Interdomain Routing (CIDR) format, in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.

If you specify icmp and also specify the any-icmp-type option, the following QoS options are not available: dscp-marking, dscp-matching, internal-priority-marking, 802.1p-priority-marking, ond 802.1p-priority-matching.

On RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.

When specifying type of service (ToS), you can indicate multiple tos-value options by entering the sum of the needed ToS options. For example, to specify both max-reliability and min-delay, enter 10. To specify all options, enter 15. Values range from 0 through 15.

In a rule that includes one or more of the following parameters, the log keyword is ignored:

  • dscp-matching
  • dscp-marking
  • 802.1p-priority-matching
  • 802.1p-priority-marking
  • 802.1p-and-internal-marking

For details on 802.1p priority matching, refer to "Inspecting the 802.1p bit in the ACL for adaptive rate limiting" in the RUCKUS FastIron Traffic Management Configuration Guide.

To delete a rule from an ACL, do either of the following:

  • Enter no sequence seq-value.
  • Type no followed by the full command syntax without the sequence seq-value.

Examples

The following ACL, applied to an Ethernet interface, blocks and logs IPv4 TCP packets transmitted by Telnet from a specified host to any destination.

device# configure terminal
device(config)# ip access-list extended block_telnet
device(config-ext-ipacl-block_telnet)# sequence 10 deny tcp host 10.157.22.26 any eq telnet log
device(config-ext-ipacl-block_telnet)# sequence 20 permit ip any any
device(config-ext-ipacl-block_telnet)# exit
device(config)# interface ethernet 1/1/1
device(config-if-1/1/1)# ip access-group block_telnet in 
History
Release version Command history
08.0.50 This command was modified to support the sequence keyword and to support logging in permit rules.