A
CCESS
C
ONTROL
L
IST
C
OMMANDS
24-2IP ACLs

The commands in this section configure ACLs based on IP addresses,

TCP/UDP port number, protocol type, and TCP control code. To

configure IP ACLs, first create an access list containing the required permit

or deny rules, set a precedence mask to control the filter sequence, and

then bind the access list to one or more ports

Table 24-2 IP ACL Commands

Command Function Mode Page
access-list ip Creates an IP ACL and enters
configuration mode for standard or
extended IP ACLs
GC 24-3
permit, deny Filters packets matching a specified
source IP address
IP-
STD-ACL
24-4
permit, deny Filters packets meeting the specified
criteria, including source and
destination IP address, TCP/UDP port
number, protocol type, and TCP
control code
IP-
EXT-ACL
24-5
show ip access-list Displays the rules for configured IP
ACLs
PE 24-7
access-list ip
mask-precedence
Changes to the IP Mask mode used to
configure access control masks
GC 24-8
mask Sets a precedence mask for the ACL
rules
IP-Mask 24-9
show access-list ip
mask-precedence
Shows the ingress or egress rule masks
for IP ACLs
PE 24-14
ip access-group Adds a port to an IP ACL IC 24-14
show ip
access-group
Shows port assignments for IP ACLs PE 24-14