
A
CCESS
C
ONTROL
L
IST
C
OMMANDS
23-2
IP ACLs
The commands in this section configure ACLs based on IP addresses,
TCP/UDP port number, protocol type, and TCP control code. To
configure IP ACLs, first create an access list containing the required permit
or deny rules, set a precedence mask to control the filter sequence, and
then bind the access list to one or more ports
Table 23-2 IP ACL Commands
Command Function Mode Page
access-list ip Creates an IPv4 ACL and enters
configuration mode for standard or
extended IPv4 ACLs
GC 23-3
permit, deny Filters packets matching a specified
source IPv4 address
IP-
STD-ACL
23-4
permit, deny Filters packets meeting the specified
criteria, including source and
destination IPv4 address, TCP/UDP
port number, protocol type, and TCP
control code
IP-
EXT-ACL
23-5
show ip access-list Displays the rules for configured IPv4
ACLs
PE 23-7
access-list ip
mask-precedence
Changes to the IP Mask mode used to
configure access control masks
GC 23-8
mask Sets a precedence mask for the ACL
rules
IP-Mask 23-9
show access-list ip
mask-precedence
Shows the ingress or egress rule masks
for IP ACLs
PE 23-13
ip access-group Adds a port to an IPv4 ACL IC 23-14
show ip
access-group
Shows port assignments for IPv4
ACLs
PE 23-14
Komentarze do niniejszej Instrukcji