Professional Documents
Culture Documents
Conf Access Lists
Conf Access Lists
Contents
Introduction Prerequisites Requirements Components Used Conventions ACL Concepts Masks ACL Summarization Process ACLs Define Ports and Message Types Apply ACLs Define In, Out, Inbound, Outbound, Source, and Destination Edit ACLs Troubleshoot Types of IP ACLs Network Diagram Standard ACLs Extended ACLs Lock and Key (Dynamic ACLs) IP Named ACLs Reflexive ACLs Time-Based ACLs Using Time Ranges Commented IP ACL Entries Context-Based Access Control Authentication Proxy Turbo ACLs Distributed Time-Based ACLs Receive ACLs Infrastructure Protection ACLs Transit ACLs Cisco Support Community - Featured Conversations Related Information
Introduction
This document describes how IP access control lists (ACLs) can filter network traffic. It also contains brief descriptions of the IP ACL types, feature availability, and an example of use in a network. Access the Software Advisor (registered customers only) tool in order to determine the support of some of the more advanced Cisco IOS IP ACL features. RFC 1700 contains assigned numbers of well-known ports. RFC 1918 contains address allocation for private Internets, IP addresses which should not normally be seen on the Internet. Note: ACLs might also be used for purposes other than to filter IP traffic, for example, defining traffic to Network Address Translate (NAT) or encrypt, or filtering non-IP protocols such as AppleTalk or IPX. A discussion of these functions is outside the scope of this document.
Prerequisites Requirements
There are no specific prerequisites for this document. The concepts discussed are present in Cisco IOS Software Releases 8.3 or later. This is noted under each access list feature.
Components Used
This document discusses various types of ACLs. Some of these are present since Cisco IOS Software Releases 8.3 and others were introduced in later software releases. This is noted in the discussion of each type. The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command.
Conventions
Refer to Cisco Technical Tips Conventions for more information on document conventions.
ACL Concepts
This section describes ACL concepts.
Masks
Masks are used with IP addresses in IP ACLs to specify what should be permitted and denied. Masks in order to configure IP addresses on interfaces start with 255 and have the large values on the left side, for example, IP address 209.165.202.129 with a 255.255.255.224 mask. Masks for IP ACLs are the reverse, for example, mask 0.0.0.255. This is sometimes called an inverse mask or a wildcard mask. When the value of the mask is broken down into binary (0s and 1s), the results determine which address bits are to be considered in processing the traffic. A 0 indicates that the address bits must be considered (exact match); a 1 in the mask is a "don't care". This table further explains the concept.
Mask Example
network address (traffic that is to be processed) mask network address (binary) mask (binary) 10.1.1.0 0.0.0.255 00001010.00000001.00000001.00000000 00000000.00000000.00000000.11111111
Based on the binary mask, you can see that the first three sets (octets) must match the given binary network address exactly (00001010.00000001.00000001). The last set of numbers are "don't cares" (.11111111). Therefore, all traffic that begins with 10.1.1. matches since the last octet is "don't care". Therefore, with this mask, network addresses 10.1.1.1 through 10.1.1.255 (10.1.1.x) are processed. Subtract the normal mask from 255.255.255.255 in order to determine the ACL inverse mask. In this example, the inverse mask is determined for network address 172.16.1.0 with a normal mask of 255.255.255.0. 255.255.255.255 - 255.255.255.0 (normal mask) = 0.0.0.255 (inverse mask) Note these ACL equivalents. The source/source-wildcard of 0.0.0.0/255.255.255.255 means "any". The source/wildcard of 10.1.1.2/0.0.0.0 is the same as "host 10.1.1.2".
ACL Summarization
Note: Subnet masks can also be represented as a fixed length notation. For example, 192.168.10.0/24 represents 192.168.10.0 255.255.255.0. This list describes how to summarize a range of networks into a single network for ACL optimization. Consider these networks. 1 9 2 . 1 6 8 . 3 2 . 0 / 2 4 1 9 2 . 1 6 8 . 3 3 . 0 / 2 4 1 9 2 . 1 6 8 . 3 4 . 0 / 2 4 1 9 2 . 1 6 8 . 3 5 . 0 / 2 4 1 9 2 . 1 6 8 . 3 6 . 0 / 2 4 1 9 2 . 1 6 8 . 3 7 . 0 / 2 4 1 9 2 . 1 6 8 . 3 8 . 0 / 2 4 1 9 2 . 1 6 8 . 3 9 . 0 / 2 4 The first two octets and the last octet are the same for each network. This table is an explanation of how to summarize these into a single network. The third octet for the previous networks can be written as seen in this table, according to the octet bit position and address value for each bit. Decimal 32 33 34 35 36 37 128 0 0 0 0 0 0 64 0 0 0 0 0 0 32 1 1 1 1 1 1 16 0 0 0 0 0 0 8 0 0 0 0 0 0 4 0 0 0 0 1 1 2 0 0 1 1 0 0 1 0 1 0 1 0 1
37 38 39
0 0 0 M
0 0 0 M
1 1 1 M
0 0 0 M
0 0 0 M
1 1 1 D
0 1 1 D
1 0 1 D
Since the first five bits match, the previous eight networks can be summarized into one network (192.168.32.0/21 or 192.168.32.0 255.255.248.0). All eight possible combinations of the three low-order bits are relevant for the network ranges in question. This command defines an ACL that permits this network. If you subtract 255.255.248.0 (normal mask) from 255.255.255.255, it yields 0.0.7.255. a c c e s s l i s ta c l _ p e r m i tp e r m i ti p1 9 2 . 1 6 8 . 3 2 . 00 . 0 . 7 . 2 5 5 Consider this set of networks for further explanation. 1 9 2 . 1 6 8 . 1 4 6 . 0 / 2 4 1 9 2 . 1 6 8 . 1 4 7 . 0 / 2 4 1 9 2 . 1 6 8 . 1 4 8 . 0 / 2 4 1 9 2 . 1 6 8 . 1 4 9 . 0 / 2 4 The first two octets and the last octet are the same for each network. This table is an explanation of how to summarize these. The third octet for the previous networks can be written as seen in this table, according to the octet bit position and address value for each bit. Decimal 146 147 148 149 128 1 1 1 1 M 64 0 0 0 0 M 32 0 0 0 0 M 16 1 1 1 1 M 8 0 0 0 0 M 4 0 0 1 1 ? 2 1 1 0 0 ? 1 0 1 0 1 ?
Unlike the previous example, you cannot summarize these networks into a single network. If they are summarized to a single network, they become 192.168.144.0/21 because there are five bits similar in the third octet. This summarized network 192.168.144.0/21 covers a range of networks from 192.168.144.0 to 192.168.151.0. Among these, 192.168.144.0, 192.168.145.0, 192.168.150.0, and 192.168.151.0 networks are not in the given list of four networks. In order to cover the specific networks in question, you need a minimum of two summarized networks. The given four networks can be summarized into these two networks: For networks 192.168.146.x and 192.168.147.x, all bits match except for the last one, which is a "don't care." This can be written as 192.168.146.0/23 (or 192.168.146.0 255.255.254.0). For networks 192.168.148.x and 192.168.149.x, all bits match except for the last one, which is a "don't care." This can be written as 192.168.148.0/23 (or 192.168.148.0 255.255.254.0). This output defines a summarized ACL for the above networks. ! -T h i sc o m m a n di su s e dt oa l l o wa c c e s sa c c e s sf o rd e v i c e sw i t hI P ! -a d d r e s s e si nt h er a n g ef r o m1 9 2 . 1 6 8 . 1 4 6 . 0t o1 9 2 . 1 6 8 . 1 4 7 . 2 5 4 . a c c e s s l i s t1 0p e r m i t1 9 2 . 1 6 8 . 1 4 6 . 00 . 0 . 1 . 2 5 5
! -T h i sc o m m a n di su s e dt oa l l o wa c c e s sa c c e s sf o rd e v i c e sw i t hI P ! -a d d r e s s e si nt h er a n g ef r o m1 9 2 . 1 6 8 . 1 4 8 . 0t o1 9 2 . 1 6 8 . 1 4 9 . 2 5 4 a c c e s s l i s t1 0p e r m i t1 9 2 . 1 6 8 . 1 4 8 . 00 . 0 . 1 . 2 5 5
Process ACLs
Traffic that comes into the router is compared to ACL entries based on the order that the entries occur in the router. New statements are added to the end of the list. The router continues to look until it has a match. If no matches are found when the router reaches the end of the list, the traffic is denied. For this reason, you should have the frequently hit entries at the top of the list. There is an implied deny for traffic that is not permitted. A single-entry ACL with only one deny entry has the effect of denying all traffic. You must have at least one permit statement in an ACL or all traffic is blocked. These two ACLs (101 and 102) have the same effect. ! -T h i sc o m m a n di su s e dt op e r m i tI Pt r a f f i cf r o m1 0 . 1 . 1 . 0 ! -n e t w o r kt o1 7 2 . 1 6 . 1 . 0n e t w o r k .A l lp a c k e t sw i t has o u r c e
! -n e t w o r kt o1 7 2 . 1 6 . 1 . 0n e t w o r k .A l lp a c k e t sw i t has o u r c e ! -a d d r e s sn o ti nt h i sr a n g ew i l lb er e j e c t e d . a c c e s s l i s t1 0 1p e r m i ti p1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 51 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 5
! -T h i sc o m m a n di su s e dt op e r m i tI Pt r a f f i cf r o m1 0 . 1 . 1 . 0 ! -n e t w o r kt o1 7 2 . 1 6 . 1 . 0n e t w o r k .A l lp a c k e t sw i t has o u r c e ! -a d d r e s sn o ti nt h i sr a n g ew i l lb er e j e c t e d . a c c e s s l i s t1 0 2p e r m i ti p1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 51 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 5 a c c e s s l i s t1 0 2d e n yi pa n ya n y In this example, the last entry is sufficient. You do not need the first three entries because TCP includes Telnet, and IP includes TCP, User Datagram Protocol (UDP), and Internet Control Message Protocol (ICMP). ! -T h i sc o m m a n di su s e dt op e r m i tT e l n e tt r a f f i c ! -f r o mm a c h i n e1 0 . 1 . 1 . 2t om a c h i n e1 7 2 . 1 6 . 1 . 1 . a c c e s s l i s t1 0 1p e r m i tt c ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qt e l n e t ! -T h i sc o m m a n di su s e dt op e r m i tt c pt r a f f i cf r o m ! -1 0 . 1 . 1 . 2h o s tm a c h i n et o1 7 2 . 1 6 . 1 . 1h o s tm a c h i n e . a c c e s s l i s t1 0 1p e r m i tt c ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1 ! -T h i sc o m m a n di su s e dt op e r m i tu d pt r a f f i cf r o m ! -1 0 . 1 . 1 . 2h o s tm a c h i n et o1 7 2 . 1 6 . 1 . 1h o s tm a c h i n e . a c c e s s l i s t1 0 1p e r m i tu d ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1 ! -T h i sc o m m a n di su s e dt op e r m i ti pt r a f f i cf r o m ! -1 0 . 1 . 1 . 0n e t w o r kt o1 7 2 . 1 6 . 1 . 1 0n e t w o r k . a c c e s s l i s t1 0 1p e r m i ti p1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 51 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 5
Apply ACLs
You can define ACLs without applying them. But, the ACLs have no effect until they are applied to the interface of the router. It is a good practice to apply the ACL on the interface closest to the source of the traffic. As shown in this example, when you try to block traffic from source to destination, you can apply an inbound ACL to E0 on router A instead of an outbound list to E1 on router C. An access-list has a deny ip any any implicitly at the end of any access-list. If traffic is related to a DHCP request and if it is not explicity permitted, the traffic is dropped because when you look at DHCP request in IP, the source address is s=0.0.0.0 (Ethernet1/0), d=255.255.255.255, len 604, rcvd 2 UDP src=68, dst=67. Note that the source IP address is 0.0.0.0 and destination address is 255.255.255.255. Source port is 68 and destination 67. Hence, you should permit this kind of traffic in your access-list else the traffic is dropped due to implicit deny at the end of the statement. Note: For UDP traffic to pass through, UDP traffic must also be permited explicitly by the ACL.
Edit ACLs
When you edit an ACL, it requires special attention. For example, if you intend to delete a specific line from a numbered ACL that exists as shown here, the entire ACL is deleted. ! -T h ea c c e s s l i s t1 0 1d e n i e si c m pf r o ma n yt oa n yn e t w o r k ! -b u tp e r m i t sI Pt r a f f i cf r o ma n yt oa n yn e t w o r k . r o u t e r # c o n f i g u r et e r m i n a l E n t e rc o n f i g u r a t i o nc o m m a n d s ,o n ep e rl i n e . E n dw i t hC N T L / Z . r o u t e r ( c o n f i g ) # a c c e s s l i s t1 0 1d e n yi c m pa n ya n y r o u t e r ( c o n f i g ) # a c c e s s l i s t1 0 1p e r m i ti pa n ya n y r o u t e r ( c o n f i g ) # ^ Z r o u t e r # s h o wa c c e s s l i s t E x t e n d e dI Pa c c e s sl i s t1 0 1 d e n yi c m pa n ya n y p e r m i ti pa n ya n y r o u t e r # * M a r 90 0 : 4 3 : 1 2 . 7 8 4 :% S Y S 5 C O N F I G _ I :C o n f i g u r e df r o mc o n s o l eb yc o n s o l e r o u t e r # c o n f i g u r et e r m i n a l E n t e rc o n f i g u r a t i o nc o m m a n d s ,o n ep e rl i n e . E n dw i t hC N T L / Z . r o u t e r ( c o n f i g ) # n oa c c e s s l i s t1 0 1d e n yi c m pa n ya n y r o u t e r ( c o n f i g ) # ^ Z r o u t e r # s h o wa c c e s s l i s t r o u t e r # * M a r 90 0 : 4 3 : 2 9 . 8 3 2 :% S Y S 5 C O N F I G _ I :C o n f i g u r e df r o mc o n s o l eb yc o n s o l e Copy the configuration of the router to a TFTP server or a text editor such as Notepad in order to edit numbered ACLs. Then make any changes and copy the configuration back to the router. You can also do this. r o u t e r # c o n f i g u r et e r m i n a l E n t e rc o n f i g u r a t i o nc o m m a n d s ,o n ep e rl i n e . r o u t e r ( c o n f i g ) # i pa c c e s s l i s te x t e n d e dt e s t ! -P e r m i t sI Pt r a f f i cf r o m2 . 2 . 2 . 2h o s tm a c h i n et o3 . 3 . 3 . 3h o s tm a c h i n e . r o u t e r ( c o n f i g e x t n a c l ) # p e r m i ti ph o s t2 . 2 . 2 . 2h o s t3 . 3 . 3 . 3
! -P e r m i t sw w wt r a f f i cf r o m1 . 1 . 1 . 1h o s tm a c h i n et o5 . 5 . 5 . 5h o s tm a c h i n e . r o u t e r ( c o n f i g e x t n a c l ) # p e r m i tt c ph o s t1 . 1 . 1 . 1h o s t5 . 5 . 5 . 5e qw w w ! -P e r m i t si c m pt r a f f i cf r o ma n yt oa n yn e t w o r k . r o u t e r ( c o n f i g e x t n a c l ) # p e r m i ti c m pa n ya n y ! -P e r m i t sd n st r a f f i cf r o m6 . 6 . 6 . 6h o s tm a c h i n et o1 0 . 1 0 . 1 0 . 0n e t w o r k . r o u t e r ( c o n f i g e x t n a c l ) # p e r m i tu d ph o s t6 . 6 . 6 . 61 0 . 1 0 . 1 0 . 00 . 0 . 0 . 2 5 5e qd o m a i n r o u t e r ( c o n f i g e x t n a c l ) # ^ Z 1 d 0 0 h :% S Y S 5 C O N F I G _ I :C o n f i g u r e df r o mc o n s o l eb yc o n s o l e s l r o u t e r # s h o wa c c e s s l i s t E x t e n d e dI Pa c c e s sl i s tt e s t p e r m i ti ph o s t2 . 2 . 2 . 2h o s t3 . 3 . 3 . 3 p e r m i tt c ph o s t1 . 1 . 1 . 1h o s t5 . 5 . 5 . 5e qw w w p e r m i ti c m pa n ya n y p e r m i tu d ph o s t6 . 6 . 6 . 61 0 . 1 0 . 1 0 . 00 . 0 . 0 . 2 5 5e qd o m a i n Any deletions are removed from the ACL and any additions are made to the end of the ACL. r o u t e r # c o n f i g u r et e r m i n a l E n t e rc o n f i g u r a t i o nc o m m a n d s ,o n ep e rl i n e . E n dw i t hC N T L / Z . r o u t e r ( c o n f i g ) # i pa c c e s s l i s te x t e n d e dt e s t ! -A C Le n t r yd e l e t e d . r o u t e r ( c o n f i g e x t n a c l ) # n op e r m i ti c m pa n ya n y ! -A C Le n t r ya d d e d . r o u t e r ( c o n f i g e x t n a c l ) # p e r m i tg r eh o s t4 . 4 . 4 . 4h o s t8 . 8 . 8 . 8 r o u t e r ( c o n f i g e x t n a c l ) # ^ Z 1 d 0 0 h :% S Y S 5 C O N F I G _ I :C o n f i g u r e df r o mc o n s o l eb yc o n s o l e s l r o u t e r # s h o wa c c e s s l i s t E x t e n d e dI Pa c c e s sl i s tt e s t p e r m i ti ph o s t2 . 2 . 2 . 2h o s t3 . 3 . 3 . 3 p e r m i tt c ph o s t1 . 1 . 1 . 1h o s t5 . 5 . 5 . 5e qw w w p e r m i tu d ph o s t6 . 6 . 6 . 61 0 . 1 0 . 1 0 . 00 . 0 . 0 . 2 5 5e qd o m a i n p e r m i tg r eh o s t4 . 4 . 4 . 4h o s t8 . 8 . 8 . 8 You can also add ACL lines to numbered standard or numbered extended ACLs by sequence number in Cisco IOS. This is a sample of the configuration: Configure the extended ACL in this way: R o u t e r ( c o n f i g ) # a c c e s s l i s t1 0 1p e r m i tt c pa n ya n y R o u t e r ( c o n f i g ) # a c c e s s l i s t1 0 1p e r m i tu d pa n ya n y R o u t e r ( c o n f i g ) # a c c e s s l i s t1 0 1p e r m i ti c m pa n ya n y R o u t e r ( c o n f i g ) # e x i t R o u t e r # Issue the show access-list command in order to view the ACL entries. The sequence numbers such as 10, 20, and 30 also appear here. R o u t e r # s h o wa c c e s s l i s t E x t e n d e dI Pa c c e s sl i s t1 0 1 1 0p e r m i tt c pa n ya n y 2 0p e r m i tu d pa n ya n y 3 0p e r m i ti c m pa n ya n y Add the entry for the access list 101 with the sequence number 5. Example 1: R o u t e r # c o n f i g u r et e r m i n a l E n t e rc o n f i g u r a t i o nc o m m a n d s ,o n ep e rl i n e . E n dw i t hC N T L / Z . R o u t e r ( c o n f i g ) # i pa c c e s s l i s te x t e n d e d1 0 1 R o u t e r ( c o n f i g e x t n a c l ) # 5d e n yt c pa n ya n ye qt e l n e t R o u t e r ( c o n f i g e x t n a c l ) # e x i t R o u t e r ( c o n f i g ) # e x i t R o u t e r #
R o u t e r # In the show access-list command output, the sequence number 5 ACL is added as the first entry to the access-list 101. R o u t e r # s h o wa c c e s s l i s t E x t e n d e dI Pa c c e s sl i s t1 0 1 5d e n yt c pa n ya n ye qt e l n e t 1 0p e r m i tt c pa n ya n y 2 0p e r m i tu d pa n ya n y 3 0p e r m i ti c m pa n ya n y R o u t e r # Example 2: i n t e r n e t r o u t e r # s h o wa c c e s s l i s t s E x t e n d e dI Pa c c e s sl i s t1 0 1 1 0p e r m i tt c pa n ya n y 1 5p e r m i tt c pa n yh o s t1 7 2 . 1 6 2 . 2 . 9 2 0p e r m i tu d ph o s t1 7 2 . 1 6 . 1 . 2 1a n y 3 0p e r m i tu d ph o s t1 7 2 . 1 6 . 1 . 2 2a n y i n t e r n e t r o u t e r # c o n f i g u r et e r m i n a l E n t e rc o n f i g u r a t i o nc o m m a n d s ,o n ep e rl i n e . E n dw i t hC N T L / Z . i n t e r n e t r o u t e r ( c o n f i g ) # i pa c c e s s l i s te x t e n d e d1 0 1 i n t e r n e t r o u t e r ( c o n f i g e x t n a c l ) # 1 8p e rt c pa n yh o s t1 7 2 . 1 6 2 . 2 . 1 1 i n t e r n e t r o u t e r ( c o n f i g e x t n a c l ) # ^ Z i n t e r n e t r o u t e r # s h o wa c c e s s l i s t s E x t e n d e dI Pa c c e s sl i s t1 0 1 1 0p e r m i tt c pa n ya n y 1 5p e r m i tt c pa n yh o s t1 7 2 . 1 6 2 . 2 . 9 1 8p e r m i tt c pa n yh o s t1 7 2 . 1 6 2 . 2 . 1 1 2 0p e r m i tu d ph o s t1 7 2 . 1 6 . 1 . 2 1a n y 3 0p e r m i tu d ph o s t1 7 2 . 1 6 . 1 . 2 2a n y i n t e r n e t r o u t e r # Similarly, you can configure the standard access list in this way: i n t e r n e t r o u t e r ( c o n f i g ) # a c c e s s l i s t2p e r m i t1 7 2 . 1 6 . 1 . 2 i n t e r n e t r o u t e r ( c o n f i g ) # a c c e s s l i s t2p e r m i t1 7 2 . 1 6 . 1 . 1 0 i n t e r n e t r o u t e r ( c o n f i g ) # a c c e s s l i s t2p e r m i t1 7 2 . 1 6 . 1 . 1 1 i n t e r n e t r o u t e r # s h o wa c c e s s l i s t s S t a n d a r dI Pa c c e s sl i s t2 3 0p e r m i t1 7 2 . 1 6 . 1 . 1 1 2 0p e r m i t1 7 2 . 1 6 . 1 . 1 0 1 0p e r m i t1 7 2 . 1 6 . 1 . 2 i n t e r n e t r o u t e r ( c o n f i g ) # i pa c c e s s l i s ts t a n d a r d2 i n t e r n e t r o u t e r ( c o n f i g s t d n a c l ) # 2 5p e r1 7 2 . 1 6 . 1 . 7 i n t e r n e t r o u t e r ( c o n f i g s t d n a c l ) # 1 5p e r1 7 2 . 1 6 . 1 . 1 6 i n t e r n e t r o u t e r # s h o wa c c e s s l i s t s S t a n d a r dI Pa c c e s sl i s t2 1 5p e r m i t1 7 2 . 1 6 . 1 . 1 6 3 0p e r m i t1 7 2 . 1 6 . 1 . 1 1 2 0p e r m i t1 7 2 . 1 6 . 1 . 1 0 2 5p e r m i t1 7 2 . 1 6 . 1 . 7 1 0p e r m i t1 7 2 . 1 6 . 1 . 2 The major difference in a standard access list is that the Cisco IOS adds an entry by descending order of the IP address, not on a sequence number. This example shows the different entries, for example, how to permit an IP address (192.168.100.0) or the networks (10.10.10.0). i n t e r n e t r o u t e r # s h o wa c c e s s l i s t s S t a n d a r dI Pa c c e s sl i s t1 9 1 0p e r m i t1 9 2 . 1 6 8 . 1 0 0 . 0 1 5p e r m i t1 0 . 1 0 . 1 0 . 0 ,w i l d c a r db i t s0 . 0 . 0 . 2 5 5 1 9p e r m i t2 0 1 . 1 0 1 . 1 1 0 . 0 ,w i l d c a r db i t s0 . 0 . 0 . 2 5 5 2 5d e n ya n y Add the entry in access list 2 in order to permit the IP Address 172.22.1.1: i n t e r n e t r o u t e r ( c o n f i g ) # i pa c c e s s l i s ts t a n d a r d2
i n t e r n e t r o u t e r ( c o n f i g ) # i pa c c e s s l i s ts t a n d a r d2 i n t e r n e t r o u t e r ( c o n f i g s t d n a c l ) # 1 8p e r m i t1 7 2 . 2 2 . 1 . 1 This entry is added in the top of the list in order to give priority to the specific IP address rather than network. i n t e r n e t r o u t e r # s h o wa c c e s s l i s t s S t a n d a r dI Pa c c e s sl i s t1 9 1 0p e r m i t1 9 2 . 1 6 8 . 1 0 0 . 0 1 8p e r m i t1 7 2 . 2 2 . 1 . 1 1 5p e r m i t1 0 . 1 0 . 1 0 . 0 ,w i l d c a r db i t s0 . 0 . 0 . 2 5 5 1 9p e r m i t2 0 1 . 1 0 1 . 1 1 0 . 0 ,w i l d c a r db i t s0 . 0 . 0 . 2 5 5 2 5d e n y a n y Note: The previous ACLs are not supported in Security Appliance such as the ASA/PIX Firewall. Guidelines to change access-lists when they are applied to crypto maps If you add to an existing access-list configuration, there is no need to remove the crypto map. If you add to them directly without the removal of the crypto map, then that is supported and acceptable. If you need to modify or delete access-list entry from an existing access-lists, then you must remove the crypto map from the interface. After you remove crypto map, make all changes to the access-list and re-add the crypto map. If you make changes such as the deletion of the access-list without the removal of the crypto map, this is not supported and can result in unpredictable behavior.
6. Restart caching. c o n f i gi n t e r f a c e i pr o u t e c a c h e
Types of IP ACLs
This section of the document describes ACL types.
Network Diagram
Standard ACLs
Standard ACLs are the oldest type of ACL. They date back to as early as Cisco IOS Software Release 8.3. Standard ACLs control traffic by the comparison of the source address of the IP packets to the addresses configured in the ACL. This is the command syntax format of a standard ACL. a c c e s s l i s ta c c e s s l i s t n u m b e r{ p e r m i t | d e n y } { h o s t | s o u r c es o u r c e w i l d c a r d | a n y } In all software releases, the access-list-number can be anything from 1 to 99. In Cisco IOS Software Release 12.0.1, standard ACLs begin to use additional numbers (1300 to 1999). These additional numbers are referred to as expanded IP ACLs. Cisco IOS Software Release 11.2 added the ability to use list name in standard ACLs. A source/source-wildcard setting of 0.0.0.0/255.255.255.255 can be specified as any. The wildcard can be omitted if it is all zeros. Therefore, host 10.1.1.2 0.0.0.0 is the same as host 10.1.1.2. After the ACL is defined, it must be applied to the interface (inbound or outbound). In early software releases, out was the default when a keyword out or in was not specified. The direction must be specified in later software releases. i n t e r f a c e< i n t e r f a c e > i pa c c e s s g r o u pn u m b e r{ i n | o u t } This is an example of the use of a standard ACL in order to block all traffic except that from source 10.1.1.x. i n t e r f a c eE t h e r n e t 0 / 0 i pa d d r e s s1 0 . 1 . 1 . 12 5 5 . 2 5 5 . 2 5 5 . 0 i pa c c e s s g r o u p1i n a c c e s s l i s t1p e r m i t1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 5
Extended ACLs
Extended ACLs were introduced in Cisco IOS Software Release 8.3. Extended ACLs control traffic by the comparison of the source and destination addresses of the IP packets to the addresses configured in the ACL. This is the command syntax format of extended ACLs. Lines are wrapped here for spacing considerations.
IP
a c c e s s l i s ta c c e s s l i s t n u m b e r [ d y n a m i cd y n a m i c n a m e[ t i m e o u tm i n u t e s ] ] { d e n y | p e r m i t }p r o t o c o ls o u r c es o u r c e w i l d c a r d d e s t i n a t i o nd e s t i n a t i o n w i l d c a r d[ p r e c e d e n c ep r e c e d e n c e ] [ t o st o s ][ l o g | l o g i n p u t ][ t i m e r a n g et i m e r a n g e n a m e ]
ICMP
a c c e s s l i s ta c c e s s l i s t n u m b e r [ d y n a m i cd y n a m i c n a m e[ t i m e o u tm i n u t e s ] ] { d e n y | p e r m i t }i c m ps o u r c es o u r c e w i l d c a r d d e s t i n a t i o nd e s t i n a t i o n w i l d c a r d [ i c m p t y p e[ i c m p c o d e ]| i c m p m e s s a g e ] [ p r e c e d e n c ep r e c e d e n c e ][ t o st o s ][ l o g | l o g i n p u t ]
[ p r e c e d e n c ep r e c e d e n c e ][ t o st o s ][ l o g | l o g i n p u t ] [ t i m e r a n g et i m e r a n g e n a m e ]
TCP
a c c e s s l i s ta c c e s s l i s t n u m b e r [ d y n a m i cd y n a m i c n a m e[ t i m e o u tm i n u t e s ] ] { d e n y | p e r m i t }t c ps o u r c es o u r c e w i l d c a r d[ o p e r a t o r[ p o r t ] ] d e s t i n a t i o nd e s t i n a t i o n w i l d c a r d[ o p e r a t o r[ p o r t ] ] [ e s t a b l i s h e d ][ p r e c e d e n c ep r e c e d e n c e ][ t o st o s ] [ l o g | l o g i n p u t ][ t i m e r a n g et i m e r a n g e n a m e ]
UDP
a c c e s s l i s ta c c e s s l i s t n u m b e r [ d y n a m i cd y n a m i c n a m e[ t i m e o u tm i n u t e s ] ] { d e n y | p e r m i t }u d ps o u r c es o u r c e w i l d c a r d[ o p e r a t o r[ p o r t ] ] d e s t i n a t i o nd e s t i n a t i o n w i l d c a r d[ o p e r a t o r[ p o r t ] ] [ p r e c e d e n c ep r e c e d e n c e ][ t o st o s ][ l o g | l o g i n p u t ] [ t i m e r a n g et i m e r a n g e n a m e ] In all software releases, the access-list-number can be 100 to 199. In Cisco IOS Software Release 12.0.1, extended ACLs begin to use additional numbers (2000 to 2699). These additional numbers are referred to as expanded IP ACLs. Cisco IOS Software Release 11.2 added the ability to use list name in extended ACLs. The value of 0.0.0.0/255.255.255.255 can be specified as any. After the ACL is defined, it must be applied to the interface (inbound or outbound). In early software releases, out was the default when a keyword out or in was not specified. The direction must be specified in later software releases. i n t e r f a c e< i n t e r f a c e > i pa c c e s s g r o u p{ n u m b e r | n a m e }{ i n | o u t } This extended ACL is used to permit traffic on the 10.1.1.x network (inside) and to receive ping responses from the outside while it prevents unsolicited pings from people outside, permitting all other traffic. i n t e r f a c eE t h e r n e t 0 / 1 i pa d d r e s s1 7 2 . 1 6 . 1 . 22 5 5 . 2 5 5 . 2 5 5 . 0 i pa c c e s s g r o u p1 0 1i n a c c e s s l i s t1 0 1d e n yi c m pa n y1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 5e c h o a c c e s s l i s t1 0 1p e r m i ti pa n y1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 5 Note: Some applications such as network management require pings for a keepalive function. If this is the case, you might wish to limit blocking inbound pings or be more granular in permitted/denied IPs.
u s e r n a m et e s ta u t o c o m m a n da c c e s s e n a b l eh o s tt i m e o u t1 0
i n t e r f a c eE t h e r n e t 0 / 0 i pa d d r e s s1 0 . 1 . 1 . 12 5 5 . 2 5 5 . 2 5 5 . 0 i pa c c e s s g r o u p1 0 1i n a c c e s s l i s t1 0 1p e r m i tt c pa n yh o s t1 0 . 1 . 1 . 1e qt e l n e t ! -1 5( m i n u t e s )i st h ea b s o l u t et i m e o u t . a c c e s s l i s t1 0 1d y n a m i ct e s t l i s tt i m e o u t1 5p e r m i ti p1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 5 1 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 5
l i n ev t y04 l o g i nl o c a l After the user at 10.1.1.2 makes a Telnet connection to 10.1.1.1, the dynamic ACL is applied. The connection is then dropped, and the user can go to the 172.16.1.x network.
IP Named ACLs
IP named ACLs were introduced in Cisco IOS Software Release 11.2. This allows standard and extended ACLs to be given names instead of numbers. This is the command syntax format for IP named ACLs. i pa c c e s s l i s t{ e x t e n d e d | s t a n d a r d }n a m e This is a TCP example: { p e r m i t | d e n y }t c ps o u r c es o u r c e w i l d c a r d[ o p e r a t o r[ p o r t ] ] d e s t i n a t i o nd e s t i n a t i o n w i l d c a r d[ o p e r a t o r[ p o r t ] ][ e s t a b l i s h e d ] [ p r e c e d e n c ep r e c e d e n c e ][ t o st o s ][ l o g ][ t i m e r a n g et i m e r a n g e n a m e ] This is an example of the use of a named ACL in order to block all traffic except the Telnet connection from host 10.1.1.2 to host 172.16.1.1. i n t e r f a c eE t h e r n e t 0 / 0 i pa d d r e s s1 0 . 1 . 1 . 12 5 5 . 2 5 5 . 2 5 5 . 0 i pa c c e s s g r o u pi n _ t o _ o u ti n i pa c c e s s l i s te x t e n d e di n _ t o _ o u t p e r m i tt c ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qt e l n e t
Reflexive ACLs
Reflexive ACLs were introduced in Cisco IOS Software Release 11.3. Reflexive ACLs allow IP packets to be filtered based on upper-layer session information. They are generally used to allow outbound traffic and to limit inbound traffic in response to sessions that originate inside the router. Reflexive ACLs can be defined only with extended named IP ACLs. They cannot be defined with numbered or standard named IP ACLs, or with other protocol ACLs. Reflexive ACLs can be used in conjunction with other standard and static extended ACLs. This is the syntax for various reflexive ACL commands. i n t e r f a c e i pa c c e s s g r o u p{ n u m b e r | n a m e }{ i n | o u t } i pa c c e s s l i s te x t e n d e dn a m e p e r m i tp r o t o c o la n ya n yr e f l e c tn a m e[ t i m e o u t s e c o n d s ] i pa c c e s s l i s te x t e n d e dn a m e e v a l u a t en a m e This is an example of the permit of ICMP outbound and inbound traffic, while only permitting TCP traffic that has initiated from inside, other traffic is denied. i pr e f l e x i v e l i s tt i m e o u t1 2 0 i n t e r f a c eE t h e r n e t 0 / 1 i pa d d r e s s1 7 2 . 1 6 . 1 . 22 5 5 . 2 5 5 . 2 5 5 . 0 i pa c c e s s g r o u pi n b o u n d f i l t e r si n
i pa c c e s s g r o u pi n b o u n d f i l t e r si n i pa c c e s s g r o u po u t b o u n d f i l t e r so u t i pa c c e s s l i s te x t e n d e di n b o u n d f i l t e r s p e r m i ti c m p1 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 51 0 . 1 . 1 . 00 . 0 . 0 . 2 5 5 e v a l u a t et c p t r a f f i c
! -T h i st i e st h er e f l e x i v eA C Lp a r to ft h eo u t b o u n d f i l t e r sA C L , ! -c a l l e dt c p t r a f f i c ,t ot h ei n b o u n d f i l t e r sA C L . i pa c c e s s l i s te x t e n d e do u t b o u n d f i l t e r s p e r m i ti c m p1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 51 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 5 p e r m i tt c p1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 51 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 5r e f l e c tt c p t r a f f i c
! -O r ,d e f i n e st h ea b s o l u t et i m e s . a b s o l u t e[ s t a r tt i m ed a t e ][ e n dt i m ed a t e ] ! -T h et i m er a n g eu s e di nt h ea c t u a lA C L . i pa c c e s s l i s tn a m e | n u m b e r< e x t e n d e d _ d e f i n i t i o n > t i m e r a n g e n a m e _ o f _ t i m e r a n g e In this example, a Telnet connection is permitted from the inside to outside network on Monday, Wednesday, and Friday during business hours: i n t e r f a c eE t h e r n e t 0 / 0 i pa d d r e s s1 0 . 1 . 1 . 12 5 5 . 2 5 5 . 2 5 5 . 0 i pa c c e s s g r o u p1 0 1i n a c c e s s l i s t1 0 1p e r m i tt c p1 0 . 1 . 1 . 00 . 0 . 0 . 2 5 51 7 2 . 1 6 . 1 . 00 . 0 . 0 . 2 5 5 e qt e l n e tt i m e r a n g eE V E R Y O T H E R D A Y t i m e r a n g eE V E R Y O T H E R D A Y p e r i o d i cM o n d a yW e d n e s d a yF r i d a y8 : 0 0t o1 7 : 0 0
i pa d d r e s s1 0 . 1 . 1 . 12 5 5 . 2 5 5 . 2 5 5 . 0 i pa c c e s s g r o u p1 0 1i n a c c e s s l i s t1 0 1r e m a r kp e r m i t _ t e l n e t a c c e s s l i s t1 0 1p e r m i tt c ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qt e l n e t
Authentication Proxy
Authentication proxy was introduced in Cisco IOS Software Release 12.0.5.T. This requires that you have the Cisco IOS Firewall feature set. Authentication proxy is used to authenticate inbound or outbound users, or both. Users who are normally blocked by an ACL can bring up a browser to go through the firewall and authenticate on a TACACS+ or RADIUS server. The server passes additional ACL entries down to the router in order to allow the users through after authentication. Authentication proxy is similar to lock and key (dynamic ACLs). These are the differences: Lock and key is turned on by a Telnet connection to the router. Authentication proxy is turned on by HTTP through the router. Authentication proxy must use an external server. Authentication proxy can handle the addition of multiple dynamic lists. Lock and key can only add one. Authentication proxy has an absolute timeout but no idle timeout. Lock and key has both. Refer to the Cisco Secure Integrated Software Configuration Cookbook for examples of authentication proxy.
Turbo ACLs
Turbo ACLs were introduced in Cisco IOS Software Release 12.1.5.T and are found only on the 7200, 7500, and other high-end platforms. The turbo ACL feature is designed in order to process ACLs more efficiently in order to improve router performance. Use the access-list compiled command for turbo ACLs. This is an example of a compiled ACL. a c c e s s l i s t1 0 1p e r m i tt c ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qt e l n e t a c c e s s l i s t1 0 1p e r m i tt c ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qf t p a c c e s s l i s t1 0 1p e r m i tu d ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qs y s l o g a c c e s s l i s t1 0 1p e r m i tu d ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qt f t p a c c e s s l i s t1 0 1p e r m i tu d ph o s t1 0 . 1 . 1 . 2h o s t1 7 2 . 1 6 . 1 . 1e qn t p After the standard or extended ACL is defined, use the global configuration command in order to compile. ! -T e l l st h er o u t e rt oc o m p i l e . a c c e s s l i s tc o m p i l e d I n t e r f a c eE t h e r n e t 0 / 1 i pa d d r e s s1 7 2 . 1 6 . 1 . 22 5 5 . 2 5 5 . 2 5 5 . 0
i pa d d r e s s1 7 2 . 1 6 . 1 . 22 5 5 . 2 5 5 . 2 5 5 . 0 ! -A p p l i e st ot h ei n t e r f a c e . i pa c c e s s g r o u p1 0 1i n The show access-list compiled command shows statistics about the ACL.
Receive ACLs
Receive ACLs are used in order to increase security on Cisco 12000 routers by the protection of the gigabit route processor (GRP) of the router from unnecessary and potentially nefarious traffic. Receive ACLs were added as a special waiver to the maintenance throttle for Cisco IOS Software Release 12.0.21S2 and integrated into 12.0(22)S. Refer to GSR: Receive Access Control Lists for further information.
Transit ACLs
Transit ACLs are used in order to increase network security since they explicitly permit only required traffic into your network or networks. Refer to Transit Access Control Lists: Filtering at Your Edge for further information.
Want to see more? Join us by clicking here Setting up access lists to filter VLSM... cshortreed 1 Reply 9 years, 11 months ago
Downloading access lists delewitz 1 Reply 9 years, 9 months ago ACL syntax rezaalikhani 1 Reply 6 years, 8 months ago Access-Lists Switches don.click1 2 Replies 5 years, 5 months ago access lists carl_townshend 1 Reply 5 years, 4 months ago access lists carl_townshend 3 Replies 3 years, 11 months ago How can I specify different Ip adresse... mmisonne 2 Replies 4 years, 1 month ago Access list at PIX nadzri_apex 2 Replies 3 years, 10 months ago Problem when configuring access lists... dedan_at_spanimage-ke.com 5 Replies 1 year, 9
Problem when configuring access lists... dedan_at_spanimage-ke.com 5 Replies 1 year, 9 months ago Start A New Discussion Subscribe
Related Information
RFC 1700 RFC 1918 Access Lists Support Page Cisco IOS Firewall Cisco IOS Software - Support Resources Technical Support & Documentation - Cisco Systems Updated: Dec 27, 2007 Document ID: 23602
Contacts | Feedback | Help | Site Map 1992-2010 Cisco Systems, Inc. All rights reserved. Terms & Conditions | Privacy Statement | Cookie Policy | Trademarks of Cisco Systems, Inc.