Adding a Comment for an Entry in an ACL

ACL comment text describes entries in an ACL and appears in the output of show commands that display ACL information.

To add a comment, enter the remark command followed by up to 255 alphanumeric characters on the line immediately preceding an ACL entry as shown in the following example.

device(config)# ip access-list extended acl100
device(config-ext-ipacl-acl100)# remark The following line permits TCP packets
device(config-ext-ipacl-acl100)# permit tcp 192.168.4.40/24 2.2.2.2/24
device(config-ext-ipacl-acl100)# remark The following permits UDP packets
device(config-ext-ipacl-acl100)# permit udp 192.168.2.52/24 2.2.2.2/24
device(config-ext-ipacl-acl100)# remark The following line denies all IPv4 traffic
device(config-ext-ipacl-acl100)# deny ip any any

The following example shows the remark command and text for the ACL named rtr and the resulting show running-config output.

device(config)# ipv6 access-list rtr
device(config-ipv6-access-list rtr)# remark This entry permits ipv6 packets from 2001:DB8::2 to any destination
device(config-ipv6-access-list rtr)# permit ipv6 host 2001:DB8::2 any
device(config-ipv6-access-list rtr)# remark This entry denies udp packets from any source to any destination
device(config-ipv6-access-list rtr)# deny udp any any
device(config-ipv6-access-list rtr)# remark This entry denies IPv6 packets from any source to any destination
device(config-ipv6-access-list rtr)# deny ipv6 any any
device# show running-config  
ipv6 access-list rtr
 remark This entry permits ipv6 packets from 2001:DB8::2 to any destination
 permit ipv6 host 2001:DB8::2 any
 remark This entry denies udp packets from any source to any destination
 deny udp any any
 remark This entry denies IPv6 packets from any source to any destination
 deny ipv6 any any