Product guide
Rules for Defining a Match Between a Packet and an
Access Control Entry (ACE) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-33
A Configured ACL Has No Effect Until You
Display All ACLs and Their Assignments in
Configuring and Assigning an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-38
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-38
General Steps for Implementing ACLs . . . . . . . . . . . . . . . . . . . . 10-38
Types of ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-38
ACL Configuration Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-39
Standard ACL Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-40
Extended ACL Configuration Structure . . . . . . . . . . . . . . . . . . . 10-40
ACL Configuration Factors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-42
ACL Resource Consumption . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-42
The Sequence of Entries in an ACL Is Significant . . . . . . . . . . . 10-42
In Any ACL, There Will Always Be a Match . . . . . . . . . . . . . . . . 10-44
Apply It to an Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-44
Using the CLI To Create an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-44
General ACE Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-44
Using CIDR Notation To Enter the ACL Mask . . . . . . . . . . . . . . 10-45
Configuring and Assigning a Numbered, Standard ACL . . . . . . . . . 10-47
Configuring and Assigning a Numbered, Extended ACL . . . . . . . . . 10-52
Configuring a Named ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-58
Enabling or Disabling ACL Filtering on an Interface . . . . . . . . . . . . 10-61
Deleting an ACL from the Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-62
Displaying ACL Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-62
Display an ACL Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-63
Display the Content of All ACLs on the Switch . . . . . . . . . . . . . . . . . 10-63
Display the ACL Assignments for an Interface . . . . . . . . . . . . . . . . . 10-64
Displaying the Content of a Specific ACL . . . . . . . . . . . . . . . . . . . . . 10-65
Displaying the Current Per-Port ACL Resources . . . . . . . . . . . . . . . 10-67
the Switch Startup-Config File and Running-Config File . . . . . . . . . 10-68
Editing ACLs and Creating an ACL Offline . . . . . . . . . . . . . . . . . . . 10-69
Using the CLI To Edit ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-69
General Editing Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-70
Deleting Any ACE from an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . 10-70
xiv