Académique Documents
Professionnel Documents
Culture Documents
Troubleshooting
ACLs
http://vnexperts.net
ICND1 v1.01-1
http://vnexperts.net
ICND1 v1.01-2
access-list access-list-number
|access-list-number.
deny | remark} source
{permit
Uses 1 to 99 for the
[mask]
The first entry is assigned a sequence number of 10, and successive entries
are incremented by 10.
Default wildcard mask is 0.0.0.0 (only standard ACL).
no access-list access-list-number removes the entire ACL.
remark lets you add a description to the ACL.
RouterX(config-if)#
http://vnexperts.net
ICND1 v1.01-3
0.0.255.255
0
1 out
1
1 out
ICND1 v1.01-4
ICND1 v1.01-5
0.0.0.255
ICND1 v1.01-6
ICND1 v1.01-7
http://vnexperts.net
ICND1 v1.01-8
access-list access-list-number
{permit | deny}
protocol source source-wildcard
Sets parameters for this list entry
[operator port]
destination destination-wildcard
RouterX(config-if)#
[operator
port] access-listip access-group
[established]
Activates the extended list[log]
on an interface
number
{in | out}
http://vnexperts.net
ICND1 v1.01-9
ICND1 v1.01-10
0.0.0.255
any eq 23
ICND1 v1.01-11
RouterX(config-if)#
ip access-group name {in | out}
Activates the named IP ACL on an interface
http://vnexperts.net
ICND1 v1.01-12
http://vnexperts.net
ICND1 v1.01-13
http://vnexperts.net
ICND1 v1.01-14
ip access-list {standard|extended} na
remark remark
Or
RouterX(config)#
ICND1 v1.01-15
0.0.0.255
http://vnexperts.net
ICND1 v1.01-16
Verifying ACLs
RouterX# show ip interfaces e0
Ethernet0 is up, line protocol is up
Internet address is 10.1.1.11/24
Broadcast address is 255.255.255.255
Address determined by setup command
MTU is 1500 bytes
Helper address is not set
Directed broadcast forwarding is disabled
Outgoing access list is not set
Inbound access list is 1
Proxy ARP is enabled
Security level is default
Split horizon is enabled
ICMP redirects are always sent
ICMP unreachables are always sent
ICMP mask replies are never sent
IP fast switching is enabled
IP fast switching on the same interface is disabled
IP Feature Fast switching turbo vector
IP multicast fast switching is enabled
IP multicast distributed fast switching is disabled
<text ommitted>
http://vnexperts.net
ICND1 v1.01-17
ICND1 v1.01-18
ICND1 v1.01-19
ICND1 v1.01-20
ICND1 v1.01-21
ICND1 v1.01-22
ICND1 v1.01-23
10.140.1.2
10.140.2.2
10.140.3.2
10.140.4.2
10.140.5.2
10.140.6.2
10.140.7.2
10.140.8.2
10.2.2.3
10.3.3.3
10.4.4.3
10.5.5.3
10.6.6.3
10.7.7.3
10.8.8.3
10.9.9.3
10.2.2.11
10.3.3.11
10.4.4.11
10.5.5.11
10.6.6.11
10.7.7.11
10.8.8.11
10.9.9.11
SwitchH
http://vnexperts.net
ICND1 v1.01-24
Summary
Standard IPv4 ACLs allow you to filter based on source IP
address.
Extended ACLs allow you to filter based on source IP address,
destination IP address, protocol, and port number.
Named ACLs allow you to delete individual statements from
an ACL.
You can use the show access-lists and show ip interface
commands to troubleshoot common ACL configuration errors.
http://vnexperts.net
ICND1 v1.01-25