Creating and Applying an Extended IPv4 ACL

Complete the following steps to create an extended IPv4 ACL.

  1. Enter configure terminal to access global configuration mode.
    device# configure terminal
    
  2. Enter the ip access-list extended command followed by a name or ID to create the ACL and enter ACL configuration sub-mode. An ID number must be all numeric and be in the range 100 through 199. If you use a name, it must begin with an alphabetical character and contain no more than 47 characters.
    device(config)# ip access-list extended ip_ext_test
    
  3. For each rule, enter the permit or deny command, specifying the needed parameters. As an option, you can specify a sequence number followed by a permit or deny statement. Otherwise, the sequence numbers will be assigned automatically in the order of statement entry in increments of 10.
    device(config-ext-ipacl-ip_ext_test)# deny tcp host 10.157.22.26 any eq telnet log
    device(config-ext-ipacl-ip_ext_test)# permit ip any any
     
  4. Apply the ACL you created to the needed interfaces or VLANs using the ip access-group command and specify the direction. If desired, include the logging enable option to log matched statements that contain the keyword log.
    device(config-ext-ipacl-ip_ext_test)# interface ethernet 1/1/2
    device(config-if-e1000-1/1/2)# ip access-group ip_ext_test in logging enable
    device(config-if-e1000-1/1/2)# exit
    device(config)#
    

The following example includes remarks preceding each rule.

device# configure terminal
device(config)# ip access-list extended ip_ext_test
device(config-ext-ipacl-ip_ext_test)# remark Permits ICMP traffic from 10.157.22.x to 10.157.21.x:
device(config-ext-ipacl-ip_ext_test)# permit icmp 10.157.22.0/24 10.157.21.0/24
device(config-ext-ipacl-ip_ext_test)# remark Denies IGMP traffic from "rkwong" to 10.157.21.x:
device(config-ext-ipacl-ip_ext_test)# deny igmp host rkwong 10.157.21.0/24 log
device(config-ext-ipacl-ip_ext_test)# remark Denies IGRP traffic from "rkwong" to 10.157.21.x:
device(config-ext-ipacl-ip_ext_test)# deny igrp 10.157.21.0/24 host rkwong log
device(config-ext-ipacl-ip_ext_test)# remark Denies IPv4 traffic from 10.157.21.100 to 10.157.22.1, with logging:
device(config-ext-ipacl-ip_ext_test)# deny ip host 10.157.21.100 host 10.157.22.1 log
device(config-ext-ipacl-ip_ext_test)# remark Denies all OSPF traffic, with logging:
device(config-ext-ipacl-ip_ext_test)# deny ospf any any log
device(config-ext-ipacl-ip_ext_test)# remark Permits traffic not explicitly denied by the previous rules:
device(config-ext-ipacl-ip_ext_test)# permit ip any any