IPv4 Access Control Lists (ACLs)

 

Displaying ACL Configuration Data

 

 

Field

Description

 

 

IP

Used for Standard ACLs: The source IP address to which the configured mask is applied to determine

 

whether there is a match with a packet.

Src IP

Used for Extended ACLs: Same as above.

Dst IP

Used for Extended ACLs: The source and destination IP addresses to which the corresponding configured

 

masks are applied to determine whether there is a match with a packet.

Mask

The mask configured in an ACE and applied to the corresponding IP address in the ACE to determine whether

 

a packet matches the filtering criteria.

Proto

Used only in extended ACLs to specify the packet protocol type to filter. Must be either IP, TCP, or UDP. For

 

TCP protocol selections, includes the established option, if configured.

Port(s)

Used only in extended ACLs to show any TCP or UDP operator and port number(s) included in the ACE.

TOS

Used only in extended ACLs to indicate Type-of-Service setting, if any.

Precedence

Used only in extended ACLs to indicate the IP precedence setting, if any.

 

 

Display All ACLs and Their Assignments in the Routing Switch Startup-Config File and Running-Config File

The show config and show running commands include in their listings any configured ACLs. Refer to figure 9-9(page 9-39)for an example. Remember that show config lists the startup-config file and show running lists the running­ config file.

9-91