19-8
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter19 Configuring Network Security with ACLs
Configuring Router ACLs
Note In addition to numbered standard and extended ACLs, you can also create standard and extended
named IP ACLs using the supported numbers. That is, the name of a standard IP ACL can be 1 to 99;
the name of an extended IP ACL can be 100 to 199. The advantage of using named ACLs instead of
numbered lists is that you can delete individual entries from a namedlist.
Creating a Numbered Standard ACL
Beginning in privileged EXEC mode, follow these steps to create a numbered standard ACL:
Use the no access-list access-list-number global configuration command to delete the entire ACL . You
cannot delete individual ACEs from numbered access lists.
13001999 IP standard access list (expanded range) Yes
20002699 IP extended access list (expanded range) Yes
Table19-1 Access List Numbers (continued)
Access List Number Type Supported
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 access-list access-list-number {deny | permit}
source [source-wildcard] [log]Define a standard IP access list by using a source address and
wildcard.
The access-list-number is a decimal number from 1 to 99 or 1300
to 1999.
Enter deny or permit to specify whether to deny or permit access
if conditions are matched.
The source is the source address of the network or host from which
the packet is being sent specified as:
The 32-bit quantity in dotted-decimal format.
The keyword any as an abbreviation for source and
source-wildcard of 0.0.0.0 255.255.255.255. You do not need
to enter a source-wildcard.
The keyword host as an abbreviation for source and
source-wildcard of source 0.0.0.0.
(Optional) The source-wildcard applies wildcard bits to the
source.
(Optional) Enter log to create an informational logging message
about the packet that matches the entry to be sent to the console.
Step3 end Return to privileged EXEC mode.
Step4 show access-lists [number | name] Show the access list configuration.
Step5 copy running-config startup-config (Optional) Save your entries in the configuration file.