A
CCESS
C
ONTROL
L
IST
C
OMMANDS
4-115

IP ACL, Egress IP ACL, Ingress MAC ACL or Egress MAC ACL), but a

mask can be bound to up to four ACLs of the same type.

IP ACLs
Command Groups Function Page
IP ACLs Configures ACLs based on IP addresses, TCP/UDP port
number, protocol type, and TCP control code
3-11
5
MAC ACLs Configures ACLs based on hardware addresses, packet
format, and Ethernet type
3-13
3
ACL Information Displays ACLs and associated rules; shows ACLs assigned
to each port
3-14
6
Command Function Mode Page
access-list ip Creates an IP ACL and enters configuration
mode
GC 3-11
6
permit, deny Filters packets matching a specified source IP
address
STD-A
CL
3-11
7
permit, deny Filters packets meeting the specified criteria,
including source and destination IP address,
TCP/UDP port number, protocol type, and TCP
control code
EXT-A
CL
3-11
8
show ip access-list Displays the rules for configured IP ACLs PE 3-12
1
access-list ip
mask-precedence
Changes to the mode for configuring access
control masks
GC 3-12
1
mask Sets a precedence mask for the ACL rules IP-Mask 3-12
2
show access-list ip
mask-precedence
Shows the ingress or egress rule masks for IP
ACLs
PE 3-12
6
ip access-group Adds a port to an IP ACL IC 3-12
7
show ip access-group Shows port assignments for IP ACLs PE 3-12
7
map access-list ip Sets the CoS value and corresponding output
queue for packets matching an ACL rule
IC 3-12
8