sequence (permit | deny in
Standard IPv4 ACLs)
sequence seq-num { deny |
permit } { S_IPaddress [ mask ] | host S_IPaddress
| any } [
log ] [ mirror ]no sequence seq-numno sequence { deny |
permit } { S_IPaddress [ mask ] | host S_IPaddress
| any } [
log ] [ mirror ]IPv4 ACL configuration mode
IPv6 ACL configuration mode
This command configures rules to permit or drop traffic based on source addresses. You can also enable logging and mirroring.
The order of the rules in an ACL is critical, as the first matching rule stops further processing. When creating rules, specifying sequence values determines the order of rule processing. If you do not specify a sequence value, the rule is added to the end of the list. Such a rule is automatically assigned the next multiple of 10 as a sequence number.
You can specify a mask in either of the following ways:
- Wildcard mask format. The advantage of this format is that it enables you to mask any bit, for example by specifying 0.255.0.255.
- Classless Interdomain Routing (CIDR) format—in which you specify the number of bits of the prefix. For example, appending /24 to an IPv4 address is equivalent to specifying 0.0.0.255 in the wildcard mask format.
On RUCKUS ICX 7150 devices, ACL logging is not supported for egress ACLs.
For the
log keyword to trigger a log entry, logging must be enabled with the
logging enable command.
The following example shows how to configure a standard numbered ACL and apply it to incoming traffic on port 1/1/1.
device# configure terminal device(config)# ip access-list standard 1 device(config-std-ipacl-1)# sequence 10 deny host 10.157.22.26 log device(config-std-ipacl-1)# sequence 20 deny 10.157.29.12 log device(config-std-ipacl-1)# sequence 30 deny host IPHost1 log device(config-std-ipacl-1)# sequence 40 permit any device(config-std-ipacl-1)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# ip access-group 1 in