Chapter 10
| Access Control Lists
IPv4 ACLs
– 330 –
This permits all TCP packets from class C addresses 192.168.1.0 with the TCP control
code set to “SYN.”
Console(config-ext-acl)#permit tcp 192.168.1.0 255.255.255.0 any control-
flag 2 2
Console(config-ext-acl)#
Related Commands
access-list ip (326)
Time Range (149)
ip access-group
This command binds an IPv4 ACL to a port. Use the
no
form to remove the port.
Syntax
ip access-group
acl-name
in
[
time-range
time-range-name] [
counter
]
no ip access-group
acl-name
in
acl-name – Name of the ACL. (Maximum length: 32 characters)
in
– Indicates that this list applies to ingress packets.
time-range-name - Name of the time range. (Range: 1-32 characters)
counter
– Enables counter for ACL statistics.
Default Setting
None
Command Mode
Interface Configuration (Ethernet)
Command Usage
If an ACL is already bound to a port and you bind a different ACL to it, the switch
will replace the old binding with the new one.
Example
Console(config)#int eth 1/2
Console(config-if)#ip access-group david in
Console(config-if)#
Related Commands
show ip access-list (331)
Time Range (149)