Displaying IPv4 ACL Information
Use the following commands to display information about IPv4 ACLs:
The following example shows that four IPv4 ACLs are configured on the device.
device# show ip access-lists brief Standard IP access list 1: 1 entries Extended IP access list 102: 0 entries Extended IP access list 104: 0 entries Standard IP access list 11: 100 entries
The following example shows the statements defined for the IPv4 ACLs configured on the device.
device# show ip access-lists Extended IP access list 101: 1 entries 10: permit ip 1.1.1.1 1.1.1.1 any mirror Standard IP access list test1: 2 entries 10: deny host 10.157.22.26 log 20: permit any Extended IP access list icmp_pass: 1 entries 10: permit icmp any any
The following example shows all IPv4 ACLs with the interface to which they are bound and their active direction.
device# show ip access-lists bindings ACL NAME TARGET DIRECTION ========= ======= ========== Acl1 eth 3/1/2 in Acl2 lag 1 out Acl1 ve 10 in Acl2 vlan 20 in Acl3 vlan 20:lag 2 in Acl4 vlan 20:eth 2/1/1 in Acl5 ve 10:lag 3 out Acl5 ve 10:eth 1/1/1 out Acl7 cpu-ports:unit-active in
The following example displays a summary of ACLs that are active on VLAN 333.
device# show access-list accounting vlan 333 in brief ACL Accounting Table ========================================================================================================================================================== UnitID: 1 ACL Name: mirror_acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 1 ACL Name: mirror_acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 1 ACL Name: mirror_acl_ipv6 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: mirror_acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: mirror_acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: mirror_acl_ipv6 HitCnt: 0 ByteCnt: 0 UnitID: 3 ACL Name: mirror_acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 3 ACL Name: mirror_acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 3 ACL Name: mirror_acl_ipv6 HitCnt: 0 ByteCnt: 0
The following example displays IPv4 ACLs present in the running configuration.
device# show running-config access-list ip ip access-list extended acl1 sequence 10 permit ip host 192.168.10.11 any sequence 20 deny ip host 192.168.10.12 any sequence 30 deny udp any any log sequence 40 permit tcp any any mirror !