CLI Reference Guide ACL Configuration Commands
ACL Configuration Commands
command ID table
For IDs used in the following commands, refer to the command ID table below:
Number of access list. Range:
Standard IP ACL: 1 to 99, 1300 to 1999
Extended IP ACL: 100 to 199,2000 to 2699
Extended MAC ACL: 700 to 799
Extended expert ACL: 2700 to 2899
ACL SN (products can be set according to the priority)
Sequence number increment
If matched, access is denied.
If matched, access is permitted.
Protocol number. For IPv6, this field can be IPv6, icmp, tcp, udp and numbers
0 to 255. For IPv4, it can be one of eigrp, gre, ipinip, igmp, nos, ospf, icmp, udp,
tcp, esp, pcp, pim and ip, or it can be numbers 0 to 255 that represent the IP
protocol. It is described when some important protocols, such as icmp/tcp/udp,
are listed individually.
Packet source IP address (host address or network address)
Source IP address wildcard. It can be discontinuous, for example, 0.255.0.32.
Source IPv6 network address or network type
Destination IPv6 network address or network type
Differential service code point, and code point value. Range: 0 to 63
Flow label in the range 0 to 1048575
Packet destination IP address (host address or network address)
Destination IP address wildcard. It can be discontinuous, such as 0.255.0.32
Packet fragment filtering.
Note: Routers do not support the packet fragment filtering.