Creating and Applying a Standard IPv4 ACL

A standard ACL permits or denies traffic according to source address only.

Complete the following steps to create a standard ACL.

  1. Enter configure terminal to access global configuration mode.
    device# configure terminal
    
  2. Enter the ip access-list standard command followed by a name or ID number to create the ACL and enter ACL configuration sub-mode. An ID number must be all numeric and be in the range 1 through 99. If you use a name, the name must begin with an alphabetical character and be no more than 47 characters long.
    device(config)# ip access-list standard ip_stan_test
    
  3. For each rule, enter the deny or permit command followed by needed parameters. As an option, you may specify the sequence number followed by a permit or deny statement. Otherwise, the sequence numbers will be assigned automatically in the order of statement entry in increments of 10.
    device(config-std-ipacl_ip_stan_test)# deny host 10.157.22.26 log
    device(config-std-ipacl_ip_stan_test)# deny 10.157.29.12 log
    device(config-std-ipacl_ip_stan_test)# deny host IPHost1 log
    device(config-std-ipacl_ip_stan_test)# permit any
    
  4. Apply the ACL you created to the appropriate interface or VLAN and specify direction. If desired, include the logging enable option to log matched statements that contain the keyword log.
    device(config-std-ipacl_ip_stan_test)# interface ethernet 1/1/1
    device(config-if-e1000-1/1/1)# ip access-group ip_stan_test in logging enable
    

The following example configures an ACL to deny packets from three source IP addresses being received on port 1/1/1. The last rule permits all packets not explicitly denied by the first three ACL entries. (Otherwise, the implicit action is "deny".) In the example, the ACL is applied to the port along with the keywords logging enable. As a result, all deny actions, which include the keyword log, are logged.

device# configure terminal
device(config)# ip access-list standard ip_stan_test
device(config-std-ipacl_ip_stan_test)# deny host 10.157.22.26 log
device(config-std-ipacl_ip_stan_test)# deny 10.157.29.12 log
device(config-std-ipacl_ip_stan_test)# deny host IPHost1 log
device(config-std-ipacl_ip_stan_test)# permit any
device(config-std-ipacl_ip_stan_test)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ip access-group ip_stan_test in logging enable
device(config-if-e1000-1/1/1)# exit
device(config)#

The following example is the result of entering show access-list all for the previously configured ACL.

device# show access-list all

Standard IP access list ip_stan_test: 4 entries
10: deny host 10.157.22.26 log 
20: deny host 10.157.29.12 log 
30: deny host IPHost1 log
40: permit any 

The following example includes remarks preceding each rule. For more information on adding remarks, refer to Adding a Comment for an Entry in an ACL.

device(config)# ip access-list standard 10
device(config-std-ipacl-10)# remark server-lab10-backup
device(config-std-ipacl-10)# permit host 192.168.100.14  
device(config-std-ipacl-10)# remark clients-lab10
device(config-std-ipacl-10)# permit 192.168.100.0 0.0.0.248
device(config-std-ipacl-10)# exit
device(config)#